CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
68881 | CVE-2014-1586 | Candidate | content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigates away. | Assigned (20140116) | None (candidate not yet proposed) | View | |
69137 | CVE-2014-1842 | Candidate | Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot) in the search-bar value. | Assigned (20140202) | None (candidate not yet proposed) | View | |
69393 | CVE-2014-2098 | Candidate | libavcodec/wmalosslessdec.c in FFmpeg before 2.1.4 uses an incorrect data-structure size for certain coefficients, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted WMA data. | Assigned (20140224) | None (candidate not yet proposed) | View | |
69649 | CVE-2014-2354 | Candidate | Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | Assigned (20140313) | None (candidate not yet proposed) | View | |
4369 | CVE-2001-1569 | Candidate | Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 1350 of 20943, showing 5 records out of 104715 total, starting on record 6746, ending on 6750