CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67577 | CVE-2014-0168 | Candidate | Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page. | Assigned (20131203) | None (candidate not yet proposed) | View | |
2297 | CVE-2000-0721 | Candidate | The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses. | Proposed (20000921) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:flagship-incorrect-permissions(5114) | View |
67833 | CVE-2014-0424 | Candidate | Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0418. | Assigned (20131212) | None (candidate not yet proposed) | View | |
68089 | CVE-2014-0680 | Candidate | Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038. | Assigned (20140102) | None (candidate not yet proposed) | View | |
2809 | CVE-2000-1242 | Candidate | The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access. | Assigned (20061209) | None (candidate not yet proposed) | View |
Page 20389 of 20943, showing 5 records out of 104715 total, starting on record 101941, ending on 101945