CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4332  CVE-2001-1532  Candidate  WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.  Assigned (20050714)  None (candidate not yet proposed)    View
69868  CVE-2014-2573  Candidate  The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.  Assigned (20140321)  None (candidate not yet proposed)    View
4588  CVE-2002-0196  Entry  GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.        View
70124  CVE-2014-2829  Candidate  Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.  Assigned (20140410)  None (candidate not yet proposed)    View
70380  CVE-2014-3085  Candidate  systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.  Assigned (20140429)  None (candidate not yet proposed)    View

Page 19347 of 20943, showing 5 records out of 104715 total, starting on record 96731, ending on 96735

Actions