CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70406  CVE-2014-3111  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Printer Model field to the Printer Management page, (2) Image Name field to the Image Management page, (3) Storage Group Name field to the Storage Management page, (4) Username field to the User Cleanup FOG Configuration page, or (5) Directory Path field to the Directory Cleaner FOG Configuration page.  Assigned (20140429)  None (candidate not yet proposed)    View
5126  CVE-2002-0736  Entry  Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.        View
70662  CVE-2014-3366  Candidate  SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089.  Assigned (20140507)  None (candidate not yet proposed)    View
5382  CVE-2002-0994  Candidate  SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
70918  CVE-2014-3622  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140514)  None (candidate not yet proposed)    View

Page 491 of 20943, showing 5 records out of 104715 total, starting on record 2451, ending on 2455

Actions