CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69883  CVE-2014-2588  Candidate  Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.  Assigned (20140323)  None (candidate not yet proposed)    View
70139  CVE-2014-2844  Candidate  Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote authenticated administrators to inject arbitrary web script or HTML via the new parameter in the SysUser module to admin.  Assigned (20140410)  None (candidate not yet proposed)    View
70395  CVE-2014-3100  Candidate  Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on cryptographic operations, via a long key name.  Assigned (20140429)  None (candidate not yet proposed)    View
70651  CVE-2014-3355  Candidate  The metadata flow feature in Cisco IOS 15.1 through 15.3 and IOS XE 3.3.xXO before 3.3.1XO, 3.6.xS and 3.7.xS before 3.7.6S, and 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S allows remote attackers to cause a denial of service (device reload) via malformed RSVP packets, aka Bug ID CSCug75942.  Assigned (20140507)  None (candidate not yet proposed)    View
70907  CVE-2014-3611  Candidate  Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation.  Assigned (20140514)  None (candidate not yet proposed)    View

Page 20526 of 20943, showing 5 records out of 104715 total, starting on record 102626, ending on 102630

Actions