CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5619 | CVE-2002-1235 | Candidate | The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Cox | Cox> Addref: REDHAT:RHSA-2002:250 | View |
71155 | CVE-2014-3859 | Candidate | libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv. | Assigned (20140525) | None (candidate not yet proposed) | View | |
71411 | CVE-2014-4115 | Candidate | fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (reserved-memory write) by connecting a crafted USB device, aka "Microsoft Windows Disk Partition Driver Elevation of Privilege Vulnerability." | Assigned (20140612) | None (candidate not yet proposed) | View | |
6131 | CVE-2002-1749 | Candidate | Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges. | Assigned (20050621) | None (candidate not yet proposed) | View | |
71667 | CVE-2014-4371 | Candidate | The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4419, CVE-2014-4420, and CVE-2014-4421. | Assigned (20140620) | None (candidate not yet proposed) | View |
Page 19306 of 20943, showing 5 records out of 104715 total, starting on record 96526, ending on 96530