CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68082  CVE-2014-0673  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950.  Assigned (20140102)  None (candidate not yet proposed)    View
2802  CVE-2000-1235  Candidate  The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.  Assigned (20050714)  None (candidate not yet proposed)    View
68338  CVE-2014-0929  Candidate  Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that trigger follow actions.  Assigned (20140106)  None (candidate not yet proposed)    View
68594  CVE-2014-1299  Candidate  WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.  Assigned (20140108)  None (candidate not yet proposed)    View
68850  CVE-2014-1555  Candidate  Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.  Assigned (20140116)  None (candidate not yet proposed)    View

Page 19830 of 20943, showing 5 records out of 104715 total, starting on record 99146, ending on 99150

Actions