CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67825  CVE-2014-0416  Candidate  Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity via vectors related to JAAS. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to how principals are set for the Subject class, which allows attackers to escape the sandbox using deserialization of a crafted Subject instance.  Assigned (20131212)  None (candidate not yet proposed)    View
2545  CVE-2000-0976  Entry  Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.        View
68081  CVE-2014-0672  Candidate  The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows remote authenticated users to download arbitrary recordings via a request to this interface.  Assigned (20140102)  None (candidate not yet proposed)    View
2801  CVE-2000-1234  Candidate  violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.  Assigned (20050714)  None (candidate not yet proposed)    View
68337  CVE-2014-0928  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140106)  None (candidate not yet proposed)    View

Page 19745 of 20943, showing 5 records out of 104715 total, starting on record 98721, ending on 98725

Actions