CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5619  CVE-2002-1235  Candidate  The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Cox  Cox> Addref: REDHAT:RHSA-2002:250  View
71155  CVE-2014-3859  Candidate  libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.  Assigned (20140525)  None (candidate not yet proposed)    View
71411  CVE-2014-4115  Candidate  fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (reserved-memory write) by connecting a crafted USB device, aka "Microsoft Windows Disk Partition Driver Elevation of Privilege Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View
6131  CVE-2002-1749  Candidate  Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges.  Assigned (20050621)  None (candidate not yet proposed)    View
71667  CVE-2014-4371  Candidate  The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4419, CVE-2014-4420, and CVE-2014-4421.  Assigned (20140620)  None (candidate not yet proposed)    View

Page 19306 of 20943, showing 5 records out of 104715 total, starting on record 96526, ending on 96530

Actions