CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4332 | CVE-2001-1532 | Candidate | WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions. | Assigned (20050714) | None (candidate not yet proposed) | View | |
69868 | CVE-2014-2573 | Candidate | The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image. | Assigned (20140321) | None (candidate not yet proposed) | View | |
4588 | CVE-2002-0196 | Entry | GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root. | View | |||
70124 | CVE-2014-2829 | Candidate | Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack. | Assigned (20140410) | None (candidate not yet proposed) | View | |
70380 | CVE-2014-3085 | Candidate | systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter. | Assigned (20140429) | None (candidate not yet proposed) | View |
Page 19347 of 20943, showing 5 records out of 104715 total, starting on record 96731, ending on 96735