CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68591  CVE-2014-1296  Candidate  CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header"s value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.  Assigned (20140108)  None (candidate not yet proposed)    View
3311  CVE-2001-0494  Entry  Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.        View
68847  CVE-2014-1552  Candidate  Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect.  Assigned (20140116)  None (candidate not yet proposed)    View
3567  CVE-2001-0760  Entry  Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.        View
69103  CVE-2014-1808  Candidate  Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."  Assigned (20140129)  None (candidate not yet proposed)    View

Page 19586 of 20943, showing 5 records out of 104715 total, starting on record 97926, ending on 97930

Actions