CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4342  CVE-2001-1542  Candidate  NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments.  Assigned (20050714)  None (candidate not yet proposed)    View
69878  CVE-2014-2583  Candidate  Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.  Assigned (20140321)  None (candidate not yet proposed)    View
70134  CVE-2014-2839  Candidate  SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.  Assigned (20140410)  None (candidate not yet proposed)    View
70390  CVE-2014-3095  Candidate  The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.  Assigned (20140429)  None (candidate not yet proposed)    View
70646  CVE-2014-3350  Candidate  Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCuh84870.  Assigned (20140507)  None (candidate not yet proposed)    View

Page 20140 of 20943, showing 5 records out of 104715 total, starting on record 100696, ending on 100700

Actions