CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71439  CVE-2014-4143  Candidate  Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6341.  Assigned (20140612)  None (candidate not yet proposed)    View
6159  CVE-2002-1777  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to obtain the file name. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but Norton AntiVirus or the Office plug-in would detect the virus before it is executed.  Assigned (20050621)  None (candidate not yet proposed)    View
71695  CVE-2014-4399  Candidate  An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4397, CVE-2014-4398, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.  Assigned (20140620)  None (candidate not yet proposed)    View
6415  CVE-2002-2033  Candidate  faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00).  Assigned (20050714)  None (candidate not yet proposed)    View
71951  CVE-2014-4654  Candidate  The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a denial of service (use-after-free and system crash) by leveraging /dev/snd/controlCX access for an ioctl call.  Assigned (20140625)  None (candidate not yet proposed)    View

Page 1813 of 20943, showing 5 records out of 104715 total, starting on record 9061, ending on 9065

Actions