CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67054  CVE-2013-7107  Candidate  Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.  Assigned (20131215)  None (candidate not yet proposed)    View
67310  CVE-2013-7363  Candidate  Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via vectors involving the P4 protocol.  Assigned (20140410)  None (candidate not yet proposed)    View
67566  CVE-2014-0157  Candidate  Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.  Assigned (20131203)  None (candidate not yet proposed)    View
67822  CVE-2014-0413  Candidate  Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0426.  Assigned (20131212)  None (candidate not yet proposed)    View
68078  CVE-2014-0669  Candidate  The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attackers to bypass intended Top-Up payment restrictions via unspecified WSP packets, aka Bug ID CSCuh28371.  Assigned (20140102)  None (candidate not yet proposed)    View

Page 19521 of 20943, showing 5 records out of 104715 total, starting on record 97601, ending on 97605

Actions