CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
68333 | CVE-2014-0924 | Candidate | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring. | Assigned (20140106) | None (candidate not yet proposed) | View | |
3053 | CVE-2001-0232 | Candidate | newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters. | Proposed (20010309) | MODIFY(1) Frech | NOOP(2) Lawler, Ziese | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:newsdesk-metacharacter-command-execution(8377) | View |
68589 | CVE-2014-1294 | Candidate | WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293. | Assigned (20140108) | None (candidate not yet proposed) | View | |
3309 | CVE-2001-0492 | Candidate | Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3. | Modified (20030619-02) | ACCEPT(4) Baker, Balinsky, Cole, Oliver | MODIFY(1) Frech | NOOP(4) Christey, Wall, Williams, Ziese | CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT] | Balinsky> Vendor acknowledged the problem in a personal communication. | Frech> XF:netcruiser-server-path-disclosure(6468) | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> Fix typo (accidental URL insertion) in XF reference | View |
68845 | CVE-2014-1550 | Candidate | Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering. | Assigned (20140116) | None (candidate not yet proposed) | View |
Page 18825 of 20943, showing 5 records out of 104715 total, starting on record 94121, ending on 94125