CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67338 | CVE-2013-7391 | Candidate | The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5 due to different researcher organizations. | Assigned (20140719) | None (candidate not yet proposed) | View | |
67594 | CVE-2014-0185 | Candidate | sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client. | Assigned (20131203) | None (candidate not yet proposed) | View | |
2314 | CVE-2000-0738 | Entry | WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail. | View | |||
67850 | CVE-2014-0441 | Candidate | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect availability via unknown vectors related to Integration Broker. | Assigned (20131212) | None (candidate not yet proposed) | View | |
2570 | CVE-2000-1001 | Entry | add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the "price" hidden form variable. | View |
Page 809 of 20943, showing 5 records out of 104715 total, starting on record 4041, ending on 4045