CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68592  CVE-2014-1297  Candidate  WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.  Assigned (20140108)  None (candidate not yet proposed)    View
3312  CVE-2001-0495  Entry  Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.        View
68848  CVE-2014-1553  Candidate  Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.  Assigned (20140116)  None (candidate not yet proposed)    View
69104  CVE-2014-1809  Candidate  The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, as exploited in the wild in May 2014, aka "MSCOMCTL ASLR Vulnerability."  Assigned (20140129)  None (candidate not yet proposed)    View
3824  CVE-2001-1020  Entry  edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.        View

Page 19666 of 20943, showing 5 records out of 104715 total, starting on record 98326, ending on 98330

Actions