CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67577  CVE-2014-0168  Candidate  Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page.  Assigned (20131203)  None (candidate not yet proposed)    View
2297  CVE-2000-0721  Candidate  The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.  Proposed (20000921)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:flagship-incorrect-permissions(5114)  View
67833  CVE-2014-0424  Candidate  Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0418.  Assigned (20131212)  None (candidate not yet proposed)    View
68089  CVE-2014-0680  Candidate  Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.  Assigned (20140102)  None (candidate not yet proposed)    View
2809  CVE-2000-1242  Candidate  The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.  Assigned (20061209)  None (candidate not yet proposed)    View

Page 20389 of 20943, showing 5 records out of 104715 total, starting on record 101941, ending on 101945

Actions