CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
69883 | CVE-2014-2588 | Candidate | Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter. | Assigned (20140323) | None (candidate not yet proposed) | View | |
70139 | CVE-2014-2844 | Candidate | Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote authenticated administrators to inject arbitrary web script or HTML via the new parameter in the SysUser module to admin. | Assigned (20140410) | None (candidate not yet proposed) | View | |
70395 | CVE-2014-3100 | Candidate | Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on cryptographic operations, via a long key name. | Assigned (20140429) | None (candidate not yet proposed) | View | |
70651 | CVE-2014-3355 | Candidate | The metadata flow feature in Cisco IOS 15.1 through 15.3 and IOS XE 3.3.xXO before 3.3.1XO, 3.6.xS and 3.7.xS before 3.7.6S, and 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S allows remote attackers to cause a denial of service (device reload) via malformed RSVP packets, aka Bug ID CSCug75942. | Assigned (20140507) | None (candidate not yet proposed) | View | |
70907 | CVE-2014-3611 | Candidate | Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation. | Assigned (20140514) | None (candidate not yet proposed) | View |
Page 20526 of 20943, showing 5 records out of 104715 total, starting on record 102626, ending on 102630