CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70900 | CVE-2014-3604 | Candidate | Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | Assigned (20140514) | None (candidate not yet proposed) | View | |
5620 | CVE-2002-1236 | Entry | The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments. | View | |||
71156 | CVE-2014-3860 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20140525) | None (candidate not yet proposed) | View | |
5876 | CVE-2002-1492 | Candidate | Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | View | |
71412 | CVE-2014-4116 | Candidate | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject arbitrary web script or HTML via a modified list, aka "SharePoint Elevation of Privilege Vulnerability." | Assigned (20140612) | None (candidate not yet proposed) | View |
Page 19989 of 20943, showing 5 records out of 104715 total, starting on record 99941, ending on 99945