CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67338  CVE-2013-7391  Candidate  The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5 due to different researcher organizations.  Assigned (20140719)  None (candidate not yet proposed)    View
67594  CVE-2014-0185  Candidate  sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.  Assigned (20131203)  None (candidate not yet proposed)    View
2314  CVE-2000-0738  Entry  WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.        View
67850  CVE-2014-0441  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect availability via unknown vectors related to Integration Broker.  Assigned (20131212)  None (candidate not yet proposed)    View
2570  CVE-2000-1001  Entry  add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the "price" hidden form variable.        View

Page 809 of 20943, showing 5 records out of 104715 total, starting on record 4041, ending on 4045

Actions