CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70917  CVE-2014-3621  Candidate  The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.  Assigned (20140514)  None (candidate not yet proposed)    View
71173  CVE-2014-3877  Candidate  Incomplete blacklist vulnerability in Frams" Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup.  Assigned (20140527)  None (candidate not yet proposed)    View
71429  CVE-2014-4133  Candidate  Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4137.  Assigned (20140612)  None (candidate not yet proposed)    View
6149  CVE-2002-1767  Candidate  Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long command line argument.  Assigned (20050621)  None (candidate not yet proposed)    View
71685  CVE-2014-4389  Candidate  Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted API arguments.  Assigned (20140620)  None (candidate not yet proposed)    View

Page 1552 of 20943, showing 5 records out of 104715 total, starting on record 7756, ending on 7760

Actions