CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
71670 | CVE-2014-4374 | Candidate | NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | Assigned (20140620) | None (candidate not yet proposed) | View | |
6390 | CVE-2002-2008 | Candidate | Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71926 | CVE-2014-4629 | Candidate | EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via unspecified vectors related to an insecure direct object reference. | Assigned (20140624) | None (candidate not yet proposed) | View | |
6646 | CVE-2002-2264 | Candidate | Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might be the same issue as CVE-2002-2185, but there are insufficient details to be certain. | Assigned (20071017) | None (candidate not yet proposed) | View | |
72182 | CVE-2014-4885 | Candidate | The CPWORLD Close Protection World (aka com.tapatalk.closeprotectionworldcom) application 3.4.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140710) | None (candidate not yet proposed) | View |
Page 20150 of 20943, showing 5 records out of 104715 total, starting on record 100746, ending on 100750