CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70636  CVE-2014-3340  Candidate  Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166.  Assigned (20140507)  None (candidate not yet proposed)    View
70892  CVE-2014-3596  Candidate  The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.  Assigned (20140514)  None (candidate not yet proposed)    View
5612  CVE-2002-1228  Candidate  Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.  Modified (20050510)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Christey, Cox | REVIEWING(1) Wall  Christey> BID:5986 | URL:http://www.securityfocus.com/bid/5986 | CERT-VN:VU#855635 | URL:http://www.kb.cert.org/vuls/id/855635  View
71148  CVE-2014-3852  Candidate  Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.  Assigned (20140523)  None (candidate not yet proposed)    View
5868  CVE-2002-1484  Candidate  DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> The default behavior is the verbose debug messages, so the description should indicate that this is the default configuration.  View

Page 19359 of 20943, showing 5 records out of 104715 total, starting on record 96791, ending on 96795

Actions