CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70919 | CVE-2014-3623 | Candidate | Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors. | Assigned (20140514) | None (candidate not yet proposed) | View | |
71175 | CVE-2014-3879 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20140527) | None (candidate not yet proposed) | View | |
71431 | CVE-2014-4135 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20140612) | None (candidate not yet proposed) | View | |
6151 | CVE-2002-1769 | Candidate | Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege. | Assigned (20050621) | None (candidate not yet proposed) | View | |
71687 | CVE-2014-4391 | Candidate | The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bundles, which allows remote attackers to bypass intended app-author restrictions by omitting an execution-related resource. | Assigned (20140620) | None (candidate not yet proposed) | View |
Page 1178 of 20943, showing 5 records out of 104715 total, starting on record 5886, ending on 5890