CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
69627 | CVE-2014-2332 | Candidate | Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330. | Assigned (20140312) | None (candidate not yet proposed) | View | |
4347 | CVE-2001-1547 | Candidate | Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code. | Assigned (20050714) | None (candidate not yet proposed) | View | |
69883 | CVE-2014-2588 | Candidate | Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter. | Assigned (20140323) | None (candidate not yet proposed) | View | |
4603 | CVE-2002-0211 | Entry | Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed. | View | |||
70139 | CVE-2014-2844 | Candidate | Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote authenticated administrators to inject arbitrary web script or HTML via the new parameter in the SysUser module to admin. | Assigned (20140410) | None (candidate not yet proposed) | View |
Page 20548 of 20943, showing 5 records out of 104715 total, starting on record 102736, ending on 102740