CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
68085 | CVE-2014-0676 | Candidate | Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367. | Assigned (20140102) | None (candidate not yet proposed) | View | |
2805 | CVE-2000-1238 | Candidate | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages. | Assigned (20051116) | None (candidate not yet proposed) | View | |
68341 | CVE-2014-0932 | Candidate | Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulfillment Foundation 9.0 before HF85 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | Assigned (20140106) | None (candidate not yet proposed) | View | |
3061 | CVE-2001-0240 | Entry | Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro. | View | |||
68597 | CVE-2014-1302 | Candidate | WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1. | Assigned (20140108) | None (candidate not yet proposed) | View |
Page 20065 of 20943, showing 5 records out of 104715 total, starting on record 100321, ending on 100325