CVE List

Id CVE No. Status Description Phase Votes Comments Actions
75261  CVE-2014-7960  Candidate  OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.  Assigned (20141007)  None (candidate not yet proposed)    View
9981  CVE-2004-1553  Candidate  SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.  Assigned (20050220)  None (candidate not yet proposed)    View
75517  CVE-2014-8216  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141010)  None (candidate not yet proposed)    View
10237  CVE-2004-1810  Candidate  The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array.  Assigned (20050504)  None (candidate not yet proposed)    View
75773  CVE-2014-8472  Candidate  CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.  Assigned (20141024)  None (candidate not yet proposed)    View

Page 20718 of 20943, showing 5 records out of 104715 total, starting on record 103586, ending on 103590

Actions