CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70141  CVE-2014-2846  Candidate  Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.  Assigned (20140410)  None (candidate not yet proposed)    View
4861  CVE-2002-0469  Candidate  Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA"s, which could allow local users to gain privileges.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
70397  CVE-2014-3102  Candidate  Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140429)  None (candidate not yet proposed)    View
70653  CVE-2014-3357  Candidate  Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets, aka Bug ID CSCul90866.  Assigned (20140507)  None (candidate not yet proposed)    View
70909  CVE-2014-3613  Candidate  cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.  Assigned (20140514)  None (candidate not yet proposed)    View

Page 20711 of 20943, showing 5 records out of 104715 total, starting on record 103551, ending on 103555

Actions