CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70382  CVE-2014-3087  Candidate  callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.  Assigned (20140429)  None (candidate not yet proposed)    View
5102  CVE-2002-0712  Candidate  Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.  Assigned (20020719)  None (candidate not yet proposed)    View
70638  CVE-2014-3342  Candidate  The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka Bug IDs CSCuq42336, CSCuq76853, CSCuq76873, and CSCuq45383.  Assigned (20140507)  None (candidate not yet proposed)    View
70894  CVE-2014-3598  Candidate  The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.  Assigned (20140514)  None (candidate not yet proposed)    View
71150  CVE-2014-3854  Candidate  Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter.  Assigned (20140523)  None (candidate not yet proposed)    View

Page 19524 of 20943, showing 5 records out of 104715 total, starting on record 97616, ending on 97620

Actions