CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68622  CVE-2014-1327  Candidate  WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.  Assigned (20140108)  None (candidate not yet proposed)    View
68878  CVE-2014-1583  Candidate  The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly restrict toJSON calls, which allows remote attackers to bypass the Same Origin Policy via crafted API calls that access sensitive information within the JSON data of an alarm.  Assigned (20140116)  None (candidate not yet proposed)    View
69134  CVE-2014-1839  Candidate  The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.  Assigned (20140202)  None (candidate not yet proposed)    View
69390  CVE-2014-2095  Candidate  Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory.  Assigned (20140224)  None (candidate not yet proposed)    View
69646  CVE-2014-2351  Candidate  SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.  Assigned (20140313)  None (candidate not yet proposed)    View

Page 1119 of 20943, showing 5 records out of 104715 total, starting on record 5591, ending on 5595

Actions