CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69104  CVE-2014-1809  Candidate  The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, as exploited in the wild in May 2014, aka "MSCOMCTL ASLR Vulnerability."  Assigned (20140129)  None (candidate not yet proposed)    View
69360  CVE-2014-2065  Candidate  Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.  Assigned (20140219)  None (candidate not yet proposed)    View
69616  CVE-2014-2321  Candidate  web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.  Assigned (20140310)  None (candidate not yet proposed)    View
4336  CVE-2001-1536  Candidate  Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.  Assigned (20050714)  None (candidate not yet proposed)    View
69872  CVE-2014-2577  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the Transform Content Center in Bottomline Technologies Transform Foundation Server before 4.3.1 Patch 8 and 5.x before 5.2 Patch 7 allow remote attackers to inject arbitrary web script or HTML via the (1) pn parameter to index.fsp/document.pdf, (2) db or (3) referer parameter to index.fsp/index.fsp, or (4) PATH_INFO to the default URI.  Assigned (20140321)  None (candidate not yet proposed)    View

Page 19677 of 20943, showing 5 records out of 104715 total, starting on record 98381, ending on 98385

Actions