CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68867  CVE-2014-1572  Candidate  The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.  Assigned (20140116)  None (candidate not yet proposed)    View
3587  CVE-2001-0780  Candidate  Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.  Proposed (20011012)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Frech> XF:directory-pro-directory-traversal(6632) | All references point to CGI with the name of | directorypro.cgi, not cosmicpro.cgi as listed in description. | Christey> Not sure how cosmicpro.cgi got in there. It should be | directorypro.cgi as indicated by Andre.  View
69123  CVE-2014-1828  Candidate  The iThoughts web server in the iThoughtsHD app 4.19 for iOS on iPad devices allows remote attackers to cause a denial of service (disk consumption) by uploading a large file.  Assigned (20140129)  None (candidate not yet proposed)    View
3843  CVE-2001-1039  Candidate  The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.  Proposed (20020131)  ACCEPT(2) Foat, Green | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:jetdirect-jetadmin-telnet-access(6950)  View
69379  CVE-2014-2084  Candidate  Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote attackers to obtain sensitive information via a request to (1) scripts/commands/getSystemInformation or (2) scripts/commands/getNetworkConfigurationInfo, cause a denial of service (reboot) via a request to scripts/commands/reboot, or cause a denial of service (shutdown) via a request to scripts/commands/shutdown.  Assigned (20140219)  None (candidate not yet proposed)    View

Page 244 of 20943, showing 5 records out of 104715 total, starting on record 1216, ending on 1220

Actions