CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5387  CVE-2002-0999  Candidate  Multiple SQL injection vulnerabilities in CARE 2002 before beta 1.0.02 allow remote attackers to perform unauthorized database operations.  Modified (20070314)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
70923  CVE-2014-3627  Candidate  The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.  Assigned (20140514)  None (candidate not yet proposed)    View
5643  CVE-2002-1259  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1286. Reason: This candidate is a reservation duplicate of CVE-2002-1286. Notes: All CVE users should reference CVE-2002-1286 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20021104)  None (candidate not yet proposed)    View
71179  CVE-2014-3883  Candidate  Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.  Assigned (20140527)  None (candidate not yet proposed)    View
5899  CVE-2002-1515  Candidate  Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter.  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View

Page 885 of 20943, showing 5 records out of 104715 total, starting on record 4421, ending on 4425

Actions