CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70382 | CVE-2014-3087 | Candidate | callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | Assigned (20140429) | None (candidate not yet proposed) | View | |
5102 | CVE-2002-0712 | Candidate | Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations. | Assigned (20020719) | None (candidate not yet proposed) | View | |
70638 | CVE-2014-3342 | Candidate | The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka Bug IDs CSCuq42336, CSCuq76853, CSCuq76873, and CSCuq45383. | Assigned (20140507) | None (candidate not yet proposed) | View | |
70894 | CVE-2014-3598 | Candidate | The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image. | Assigned (20140514) | None (candidate not yet proposed) | View | |
71150 | CVE-2014-3854 | Candidate | Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter. | Assigned (20140523) | None (candidate not yet proposed) | View |
Page 19524 of 20943, showing 5 records out of 104715 total, starting on record 97616, ending on 97620