CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3076  CVE-2001-0255  Candidate  FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.  Proposed (20010404)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop    View
68612  CVE-2014-1317  Candidate  iBooks Commerce in Apple OS X before 10.9.4 places Apple ID credentials in the iBooks log, which allows local users to obtain sensitive information by reading this file.  Assigned (20140108)  None (candidate not yet proposed)    View
3332  CVE-2001-0518  Entry  Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.        View
68868  CVE-2014-1573  Candidate  Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.  Assigned (20140116)  None (candidate not yet proposed)    View
3588  CVE-2001-0781  Candidate  Buffer overflow in SpoonFTP 1.0.0.12 allows remote attackers to execute arbitrary code via a long argument to the commands (1) CWD or (2) LIST.  Proposed (20011012)  ACCEPT(3) Armstrong, Foat, Frech | NOOP(2) Cole, Wall    View

Page 328 of 20943, showing 5 records out of 104715 total, starting on record 1636, ending on 1640

Actions