CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71676  CVE-2014-4380  Candidate  The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code in the kernel"s context via a crafted application.  Assigned (20140620)  None (candidate not yet proposed)    View
6396  CVE-2002-2014  Candidate  Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.  Assigned (20050714)  None (candidate not yet proposed)    View
71932  CVE-2014-4635  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum Web Development Kit (WDK) before 6.8 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140624)  None (candidate not yet proposed)    View
6652  CVE-2002-2270  Candidate  Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.  Assigned (20071017)  None (candidate not yet proposed)    View
72188  CVE-2014-4891  Candidate  The CT iHub (aka com.concursive.ctihub) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View

Page 20023 of 20943, showing 5 records out of 104715 total, starting on record 100111, ending on 100115

Actions