CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69882  CVE-2014-2587  Candidate  SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter).  Assigned (20140323)  None (candidate not yet proposed)    View
4602  CVE-2002-0210  Candidate  setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
70138  CVE-2014-2843  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140410)  None (candidate not yet proposed)    View
4858  CVE-2002-0466  Candidate  Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrowse.asp.  Proposed (20020611)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
70394  CVE-2014-3099  Candidate  Unspecified vulnerability in the Security component in IBM Systems Director 6.3.0 through 6.3.5 allows local users to obtain sensitive information via unknown vectors.  Assigned (20140429)  None (candidate not yet proposed)    View

Page 20471 of 20943, showing 5 records out of 104715 total, starting on record 102351, ending on 102355

Actions