CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67053  CVE-2013-7106  Candidate  Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c; (5) status_page_num_selector function in cgi/status.c; or (6) display_command_expansion function in cgi/config.c. NOTE: this can be exploited without authentication by leveraging CVE-2013-7107.  Assigned (20131215)  None (candidate not yet proposed)    View
67309  CVE-2013-7362  Candidate  An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.  Assigned (20140410)  None (candidate not yet proposed)    View
67565  CVE-2014-0156  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20131203)  None (candidate not yet proposed)    View
67821  CVE-2014-0412  Candidate  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.  Assigned (20131212)  None (candidate not yet proposed)    View
68077  CVE-2014-0668  Candidate  Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCue65949.  Assigned (20140102)  None (candidate not yet proposed)    View

Page 19444 of 20943, showing 5 records out of 104715 total, starting on record 97216, ending on 97220

Actions