CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69360  CVE-2014-2065  Candidate  Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.  Assigned (20140219)  None (candidate not yet proposed)    View
4080  CVE-2001-1276  Entry  ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.        View
69616  CVE-2014-2321  Candidate  web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.  Assigned (20140310)  None (candidate not yet proposed)    View
4336  CVE-2001-1536  Candidate  Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.  Assigned (20050714)  None (candidate not yet proposed)    View
69872  CVE-2014-2577  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the Transform Content Center in Bottomline Technologies Transform Foundation Server before 4.3.1 Patch 8 and 5.x before 5.2 Patch 7 allow remote attackers to inject arbitrary web script or HTML via the (1) pn parameter to index.fsp/document.pdf, (2) db or (3) referer parameter to index.fsp/index.fsp, or (4) PATH_INFO to the default URI.  Assigned (20140321)  None (candidate not yet proposed)    View

Page 19667 of 20943, showing 5 records out of 104715 total, starting on record 98331, ending on 98335

Actions