CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
68591 | CVE-2014-1296 | Candidate | CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header"s value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction. | Assigned (20140108) | None (candidate not yet proposed) | View | |
3311 | CVE-2001-0494 | Entry | Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header. | View | |||
68847 | CVE-2014-1552 | Candidate | Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect. | Assigned (20140116) | None (candidate not yet proposed) | View | |
3567 | CVE-2001-0760 | Entry | Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field. | View | |||
69103 | CVE-2014-1808 | Candidate | Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability." | Assigned (20140129) | None (candidate not yet proposed) | View |
Page 19586 of 20943, showing 5 records out of 104715 total, starting on record 97926, ending on 97930