CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68085  CVE-2014-0676  Candidate  Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.  Assigned (20140102)  None (candidate not yet proposed)    View
2805  CVE-2000-1238  Candidate  BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.  Assigned (20051116)  None (candidate not yet proposed)    View
68341  CVE-2014-0932  Candidate  Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulfillment Foundation 9.0 before HF85 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140106)  None (candidate not yet proposed)    View
3061  CVE-2001-0240  Entry  Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.        View
68597  CVE-2014-1302  Candidate  WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.  Assigned (20140108)  None (candidate not yet proposed)    View

Page 20065 of 20943, showing 5 records out of 104715 total, starting on record 100321, ending on 100325

Actions