CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3823  CVE-2001-1019  Candidate  Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
69359  CVE-2014-2064  Candidate  The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.  Assigned (20140219)  None (candidate not yet proposed)    View
69615  CVE-2014-2320  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140310)  None (candidate not yet proposed)    View
4335  CVE-2001-1535  Candidate  Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID"s from cookies and gain unauthorized access via a brute force attack.  Assigned (20050714)  None (candidate not yet proposed)    View
69871  CVE-2014-2576  Candidate  plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.  Assigned (20140321)  None (candidate not yet proposed)    View

Page 19587 of 20943, showing 5 records out of 104715 total, starting on record 97931, ending on 97935

Actions