CVE List
| Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
|---|---|---|---|---|---|---|---|
| 68622 | CVE-2014-1327 | Candidate | WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1. | Assigned (20140108) | None (candidate not yet proposed) | View | |
| 68878 | CVE-2014-1583 | Candidate | The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly restrict toJSON calls, which allows remote attackers to bypass the Same Origin Policy via crafted API calls that access sensitive information within the JSON data of an alarm. | Assigned (20140116) | None (candidate not yet proposed) | View | |
| 69134 | CVE-2014-1839 | Candidate | The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file. | Assigned (20140202) | None (candidate not yet proposed) | View | |
| 69390 | CVE-2014-2095 | Candidate | Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory. | Assigned (20140224) | None (candidate not yet proposed) | View | |
| 69646 | CVE-2014-2351 | Candidate | SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests. | Assigned (20140313) | None (candidate not yet proposed) | View |
Page 1119 of 20943, showing 5 records out of 104715 total, starting on record 5591, ending on 5595