CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70900  CVE-2014-3604  Candidate  Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject"s Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.  Assigned (20140514)  None (candidate not yet proposed)    View
5620  CVE-2002-1236  Entry  The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.        View
71156  CVE-2014-3860  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140525)  None (candidate not yet proposed)    View
5876  CVE-2002-1492  Candidate  Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox    View
71412  CVE-2014-4116  Candidate  Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject arbitrary web script or HTML via a modified list, aka "SharePoint Elevation of Privilege Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View

Page 19989 of 20943, showing 5 records out of 104715 total, starting on record 99941, ending on 99945

Actions