CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3335  CVE-2001-0521  Candidate  Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.  Proposed (20010727)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese | REVIEWING(1) Bishop  CHANGE> [Frech changed vote from ACCEPT to MODIFY] | Frech> DELREF:XF:esafe-gateway-bypass-filtering(6580) | ADDREF:XF:content-unicode-bypass-filter(6980) | Baker> Found acknowledgement in the release notes for build 71, that said: | | "15. Fixed a bug that used to cause the SmartStripping mechanism to miss some scripts in HTML pages." | | Release notes are at the following url: | ftp://ftp.ealaddin.com/pub/manuals/ESG/ESG3.x/esg_rn.zip  View
68871  CVE-2014-1576  Candidate  Heap-based buffer overflow in the nsTransformedTextRun function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to execute arbitrary code via Cascading Style Sheets (CSS) token sequences that trigger changes to capitalization style.  Assigned (20140116)  None (candidate not yet proposed)    View
69127  CVE-2014-1832  Candidate  Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.  Assigned (20140130)  None (candidate not yet proposed)    View
69383  CVE-2014-2088  Candidate  Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname.  Assigned (20140224)  None (candidate not yet proposed)    View
69639  CVE-2014-2344  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140313)  None (candidate not yet proposed)    View

Page 565 of 20943, showing 5 records out of 104715 total, starting on record 2821, ending on 2825

Actions