CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
68847 | CVE-2014-1552 | Candidate | Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect. | Assigned (20140116) | None (candidate not yet proposed) | View | |
69103 | CVE-2014-1808 | Candidate | Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability." | Assigned (20140129) | None (candidate not yet proposed) | View | |
3823 | CVE-2001-1019 | Candidate | Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
69359 | CVE-2014-2064 | Candidate | The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts. | Assigned (20140219) | None (candidate not yet proposed) | View | |
4079 | CVE-2001-1275 | Candidate | MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Christey | Christey> CALDERA:CSSA-2001-006.0 specifically says they"re not | vulnerable to this issue. So, do we remove the reference | (because they aren"t affected by this problem), or do we | keep the reference because it specifically mentions this | issue? | | Need to review the other advisories; they don"t necessarily | have the details to know whether they"re addressing this | problem or not (the overflow mentioned in these refs is | covered by CVE-2001-1274). MANDRAKE:MDKSA-2001:014 | clearly identifies this issue. | | FREEBSD:FreeBSD-SA-01:16 discussed "remote vulerabilities" | (plural), which *could* include this issue, but it is not | absolutely certain. REDHAT:RHSA-2001:003 refers to | "information protection issues," but that"s not clear enough | either. | | Thanks to John Segura of secureinfo.com for noticing this | issue. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mysql-show-grants-password(9996) | View |
Page 19595 of 20943, showing 5 records out of 104715 total, starting on record 97971, ending on 97975