CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69612  CVE-2014-2317  Candidate  SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information.  Assigned (20140307)  None (candidate not yet proposed)    View
4332  CVE-2001-1532  Candidate  WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.  Assigned (20050714)  None (candidate not yet proposed)    View
69868  CVE-2014-2573  Candidate  The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.  Assigned (20140321)  None (candidate not yet proposed)    View
70124  CVE-2014-2829  Candidate  Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.  Assigned (20140410)  None (candidate not yet proposed)    View
70380  CVE-2014-3085  Candidate  systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.  Assigned (20140429)  None (candidate not yet proposed)    View

Page 19369 of 20943, showing 5 records out of 104715 total, starting on record 96841, ending on 96845

Actions