CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68881  CVE-2014-1586  Candidate  content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigates away.  Assigned (20140116)  None (candidate not yet proposed)    View
69137  CVE-2014-1842  Candidate  Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot) in the search-bar value.  Assigned (20140202)  None (candidate not yet proposed)    View
69393  CVE-2014-2098  Candidate  libavcodec/wmalosslessdec.c in FFmpeg before 2.1.4 uses an incorrect data-structure size for certain coefficients, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted WMA data.  Assigned (20140224)  None (candidate not yet proposed)    View
69649  CVE-2014-2354  Candidate  Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.  Assigned (20140313)  None (candidate not yet proposed)    View
4369  CVE-2001-1569  Candidate  Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 1350 of 20943, showing 5 records out of 104715 total, starting on record 6746, ending on 6750

Actions