CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68847  CVE-2014-1552  Candidate  Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect.  Assigned (20140116)  None (candidate not yet proposed)    View
69103  CVE-2014-1808  Candidate  Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."  Assigned (20140129)  None (candidate not yet proposed)    View
3823  CVE-2001-1019  Candidate  Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
69359  CVE-2014-2064  Candidate  The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.  Assigned (20140219)  None (candidate not yet proposed)    View
4079  CVE-2001-1275  Candidate  MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Christey  Christey> CALDERA:CSSA-2001-006.0 specifically says they"re not | vulnerable to this issue. So, do we remove the reference | (because they aren"t affected by this problem), or do we | keep the reference because it specifically mentions this | issue? | | Need to review the other advisories; they don"t necessarily | have the details to know whether they"re addressing this | problem or not (the overflow mentioned in these refs is | covered by CVE-2001-1274). MANDRAKE:MDKSA-2001:014 | clearly identifies this issue. | | FREEBSD:FreeBSD-SA-01:16 discussed "remote vulerabilities" | (plural), which *could* include this issue, but it is not | absolutely certain. REDHAT:RHSA-2001:003 refers to | "information protection issues," but that"s not clear enough | either. | | Thanks to John Segura of secureinfo.com for noticing this | issue. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mysql-show-grants-password(9996)  View

Page 19595 of 20943, showing 5 records out of 104715 total, starting on record 97971, ending on 97975

Actions