CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71409  CVE-2014-4113  Candidate  win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View
6129  CVE-2002-1747  Candidate  Vtun 2.5b1 does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on ECB.  Assigned (20050621)  None (candidate not yet proposed)    View
71665  CVE-2014-4369  Candidate  The IOAcceleratorFamily API implementation in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via an application that uses crafted arguments.  Assigned (20140620)  None (candidate not yet proposed)    View
6385  CVE-2002-2003  Candidate  ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap.  Assigned (20050714)  None (candidate not yet proposed)    View
71921  CVE-2014-4624  Candidate  EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call.  Assigned (20140624)  None (candidate not yet proposed)    View

Page 19756 of 20943, showing 5 records out of 104715 total, starting on record 98776, ending on 98780

Actions