CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69357  CVE-2014-2062  Candidate  Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.  Assigned (20140219)  None (candidate not yet proposed)    View
69613  CVE-2014-2318  Candidate  SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.  Assigned (20140310)  None (candidate not yet proposed)    View
4333  CVE-2001-1533  Candidate  ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.  Assigned (20050714)  None (candidate not yet proposed)    View
69869  CVE-2014-2574  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140321)  None (candidate not yet proposed)    View
70125  CVE-2014-2830  Candidate  Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecified impact via unknown vectors.  Assigned (20140410)  None (candidate not yet proposed)    View

Page 19446 of 20943, showing 5 records out of 104715 total, starting on record 97226, ending on 97230

Actions