CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5100 | CVE-2002-0710 | Entry | Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter. | View | |||
70636 | CVE-2014-3340 | Candidate | Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166. | Assigned (20140507) | None (candidate not yet proposed) | View | |
5356 | CVE-2002-0968 | Entry | Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name. | View | |||
70892 | CVE-2014-3596 | Candidate | The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784. | Assigned (20140514) | None (candidate not yet proposed) | View | |
71148 | CVE-2014-3852 | Candidate | Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | Assigned (20140523) | None (candidate not yet proposed) | View |
Page 19348 of 20943, showing 5 records out of 104715 total, starting on record 96736, ending on 96740