CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68621  CVE-2014-1326  Candidate  WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.  Assigned (20140108)  None (candidate not yet proposed)    View
68877  CVE-2014-1582  Candidate  The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.  Assigned (20140116)  None (candidate not yet proposed)    View
3597  CVE-2001-0790  Candidate  Specter IDS version 4.5 and 5.0 allows a remote attacker to cause a denial of service (CPU exhaustion) via a port scan, which causes the server to consume CPU while preparing alerts.  Proposed (20011012)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:specter-ids-portscan-dos(7415)  View
69133  CVE-2014-1838  Candidate  The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.  Assigned (20140202)  None (candidate not yet proposed)    View
69389  CVE-2014-2094  Candidate  Untrusted search path vulnerability in Catfish through 0.4.0.3, when a Fedora package such as 0.4.0.2-2 is not used, allows local users to gain privileges via a Trojan horse catfish.pyc in the current working directory.  Assigned (20140224)  None (candidate not yet proposed)    View

Page 1040 of 20943, showing 5 records out of 104715 total, starting on record 5196, ending on 5200

Actions