CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70387  CVE-2014-3092  Candidate  IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.  Assigned (20140429)  None (candidate not yet proposed)    View
70643  CVE-2014-3347  Candidate  Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module, aka Bug ID CSCul77897.  Assigned (20140507)  None (candidate not yet proposed)    View
70899  CVE-2014-3603  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140514)  None (candidate not yet proposed)    View
71155  CVE-2014-3859  Candidate  libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.  Assigned (20140525)  None (candidate not yet proposed)    View
71411  CVE-2014-4115  Candidate  fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (reserved-memory write) by connecting a crafted USB device, aka "Microsoft Windows Disk Partition Driver Elevation of Privilege Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View

Page 18786 of 20943, showing 5 records out of 104715 total, starting on record 93926, ending on 93930

Actions