CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69888  CVE-2014-2593  Candidate  The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.  Assigned (20140324)  None (candidate not yet proposed)    View
70144  CVE-2014-2849  Candidate  The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.  Assigned (20140411)  None (candidate not yet proposed)    View
70400  CVE-2014-3105  Candidate  The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.  Assigned (20140429)  None (candidate not yet proposed)    View
70656  CVE-2014-3360  Candidate  Cisco IOS 12.4 and 15.0 through 15.4 and IOS XE 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; and 3.11.xS before 3.12S allow remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCul46586.  Assigned (20140507)  None (candidate not yet proposed)    View
70912  CVE-2014-3616  Candidate  nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.  Assigned (20140514)  None (candidate not yet proposed)    View

Page 41 of 20943, showing 5 records out of 104715 total, starting on record 201, ending on 205

Actions