CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71672  CVE-2014-4376  Candidate  IOKit in IOAcceleratorFamily in Apple OS X before 10.9.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted API arguments.  Assigned (20140620)  None (candidate not yet proposed)    View
6392  CVE-2002-2010  Candidate  Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.  Assigned (20050714)  None (candidate not yet proposed)    View
71928  CVE-2014-4631  Candidate  RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.  Assigned (20140624)  None (candidate not yet proposed)    View
6648  CVE-2002-2266  Candidate  NetScreen ScreenOS 2.8 through 4.0, when forwarding H.323 or Netmeeting traffic, allows remote attackers to cause a denial of service (firewall session table consumption) by establishing multiple half-open H.323 sessions, which are not cleaned up on garbage removal and do not time out for 36 hours.  Assigned (20071017)  None (candidate not yet proposed)    View
72184  CVE-2014-4887  Candidate  The Joint Radio Blues (aka com.nobexinc.wls_69685189.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View

Page 19704 of 20943, showing 5 records out of 104715 total, starting on record 98516, ending on 98520

Actions