CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
71409 | CVE-2014-4113 | Candidate | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability." | Assigned (20140612) | None (candidate not yet proposed) | View | |
6129 | CVE-2002-1747 | Candidate | Vtun 2.5b1 does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on ECB. | Assigned (20050621) | None (candidate not yet proposed) | View | |
71665 | CVE-2014-4369 | Candidate | The IOAcceleratorFamily API implementation in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via an application that uses crafted arguments. | Assigned (20140620) | None (candidate not yet proposed) | View | |
6385 | CVE-2002-2003 | Candidate | ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71921 | CVE-2014-4624 | Candidate | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call. | Assigned (20140624) | None (candidate not yet proposed) | View |
Page 19756 of 20943, showing 5 records out of 104715 total, starting on record 98776, ending on 98780