CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5386  CVE-2002-0998  Candidate  Directory traversal vulnerability in cafenews.php for CARE 2002 before beta 1.0.02 allows remote attackers to read arbitrary files via .. (dot dot) sequences and null characters in the lang parameter, which is processed by a call to the include function.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
70922  CVE-2014-3626  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140514)  None (candidate not yet proposed)    View
5642  CVE-2002-1258  Candidate  Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
71178  CVE-2014-3882  Candidate  Cross-site request forgery (CSRF) vulnerability in the Login rebuilder plugin before 1.2.0 for WordPress allows remote attackers to hijack the authentication of arbitrary users.  Assigned (20140527)  None (candidate not yet proposed)    View
5898  CVE-2002-1514  Entry  gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.        View

Page 814 of 20943, showing 5 records out of 104715 total, starting on record 4066, ending on 4070

Actions