CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3825 | CVE-2001-1021 | Candidate | Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD. | Proposed (20020131) | ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Wall | NOOP(1) Foat | View | |
69361 | CVE-2014-2066 | Candidate | Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies. | Assigned (20140219) | None (candidate not yet proposed) | View | |
69617 | CVE-2014-2322 | Candidate | lib/string_utf_support.rb in the Arabic Prawn 0.0.1 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) downloaded_file or (2) url variable. | Assigned (20140312) | None (candidate not yet proposed) | View | |
4337 | CVE-2001-1537 | Candidate | The default "basic" security setting" in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges. | Assigned (20050714) | None (candidate not yet proposed) | View | |
69873 | CVE-2014-2578 | Candidate | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20140321) | None (candidate not yet proposed) | View |
Page 19755 of 20943, showing 5 records out of 104715 total, starting on record 98771, ending on 98775