CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4349  CVE-2001-1549  Candidate  Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.  Assigned (20050714)  None (candidate not yet proposed)    View
69885  CVE-2014-2590  Candidate  The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.  Assigned (20140324)  None (candidate not yet proposed)    View
70141  CVE-2014-2846  Candidate  Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.  Assigned (20140410)  None (candidate not yet proposed)    View
4861  CVE-2002-0469  Candidate  Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA"s, which could allow local users to gain privileges.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
70397  CVE-2014-3102  Candidate  Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140429)  None (candidate not yet proposed)    View

Page 20100 of 20943, showing 5 records out of 104715 total, starting on record 100496, ending on 100500

Actions