CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68867  CVE-2014-1572  Candidate  The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.  Assigned (20140116)  None (candidate not yet proposed)    View
69123  CVE-2014-1828  Candidate  The iThoughts web server in the iThoughtsHD app 4.19 for iOS on iPad devices allows remote attackers to cause a denial of service (disk consumption) by uploading a large file.  Assigned (20140129)  None (candidate not yet proposed)    View
69379  CVE-2014-2084  Candidate  Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote attackers to obtain sensitive information via a request to (1) scripts/commands/getSystemInformation or (2) scripts/commands/getNetworkConfigurationInfo, cause a denial of service (reboot) via a request to scripts/commands/reboot, or cause a denial of service (shutdown) via a request to scripts/commands/shutdown.  Assigned (20140219)  None (candidate not yet proposed)    View
4099  CVE-2001-1295  Entry  Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command.        View
69635  CVE-2014-2340  Candidate  Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.  Assigned (20140312)  None (candidate not yet proposed)    View

Page 248 of 20943, showing 5 records out of 104715 total, starting on record 1236, ending on 1240

Actions