CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5100  CVE-2002-0710  Entry  Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter.        View
70636  CVE-2014-3340  Candidate  Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166.  Assigned (20140507)  None (candidate not yet proposed)    View
5356  CVE-2002-0968  Entry  Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name.        View
70892  CVE-2014-3596  Candidate  The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.  Assigned (20140514)  None (candidate not yet proposed)    View
71148  CVE-2014-3852  Candidate  Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.  Assigned (20140523)  None (candidate not yet proposed)    View

Page 19348 of 20943, showing 5 records out of 104715 total, starting on record 96736, ending on 96740

Actions