CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2813 | CVE-2000-1246 | Candidate | NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command. | Assigned (20100405) | None (candidate not yet proposed) | View | |
68349 | CVE-2014-0940 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Service Automation Manager 7.2.2.2 before 7.2.2.2-TIV-TSAM-LA0041 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) REST API or (2) Self Service UI. | Assigned (20140106) | None (candidate not yet proposed) | View | |
3069 | CVE-2001-0248 | Candidate | Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings. | Interim (20010911) | ACCEPT(5) Baker, Cole, Prosser, Renaud, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:ftp-glob-expansion(6332) | Prosser> HPSBUX0107-162. Probably should change description to add the | HP-UX 10.01, 10.10, 10.20, 10.24 (VVOS), 11.04 (VVOS) and 11.11 | versions of the operating system as well. Patches for all systems | referenced in the advisory. | View |
68605 | CVE-2014-1310 | Candidate | WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1. | Assigned (20140108) | None (candidate not yet proposed) | View | |
68861 | CVE-2014-1566 | Candidate | Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515. | Assigned (20140116) | None (candidate not yet proposed) | View |
Page 20098 of 20943, showing 5 records out of 104715 total, starting on record 100486, ending on 100490