CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4861  CVE-2002-0469  Candidate  Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA"s, which could allow local users to gain privileges.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
70397  CVE-2014-3102  Candidate  Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140429)  None (candidate not yet proposed)    View
5117  CVE-2002-0727  Entry  The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.        View
70653  CVE-2014-3357  Candidate  Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets, aka Bug ID CSCul90866.  Assigned (20140507)  None (candidate not yet proposed)    View
5373  CVE-2002-0985  Entry  Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.        View

Page 20709 of 20943, showing 5 records out of 104715 total, starting on record 103541, ending on 103545

Actions