CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71419  CVE-2014-4123  Candidate  Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.  Assigned (20140612)  None (candidate not yet proposed)    View
6139  CVE-2002-1757  Candidate  PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms".  Assigned (20050621)  None (candidate not yet proposed)    View
71675  CVE-2014-4379  Candidate  An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, which allows attackers to bypass the ASLR protection mechanism via a crafted application.  Assigned (20140620)  None (candidate not yet proposed)    View
6395  CVE-2002-2013  Candidate  Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.  Assigned (20050714)  None (candidate not yet proposed)    View
71931  CVE-2014-4634  Candidate  Unquoted Windows search path vulnerability in EMC Replication Manager through 5.5.2 and AppSync before 2.1.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.  Assigned (20140624)  None (candidate not yet proposed)    View

Page 19404 of 20943, showing 5 records out of 104715 total, starting on record 97016, ending on 97020

Actions