CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68880  CVE-2014-1585  Candidate  The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not properly recognize Stop Sharing actions for videos in IFRAME elements, which allows remote attackers to obtain sensitive information from the local camera by maintaining a session after the user tries to discontinue streaming.  Assigned (20140116)  None (candidate not yet proposed)    View
69136  CVE-2014-1841  Candidate  Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user"s home folder via a Move action with a .. (dot dot) in the src parameter.  Assigned (20140202)  None (candidate not yet proposed)    View
69392  CVE-2014-2097  Candidate  The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted TAK (aka Tom"s lossless Audio Kompressor) data.  Assigned (20140224)  None (candidate not yet proposed)    View
69648  CVE-2014-2353  Candidate  Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140313)  None (candidate not yet proposed)    View
4368  CVE-2001-1568  Candidate  CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 1273 of 20943, showing 5 records out of 104715 total, starting on record 6361, ending on 6365

Actions