CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5627  CVE-2002-1243  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20021101)  None (candidate not yet proposed)    View
71163  CVE-2014-3867  Candidate  The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.  Assigned (20140525)  None (candidate not yet proposed)    View
71419  CVE-2014-4123  Candidate  Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.  Assigned (20140612)  None (candidate not yet proposed)    View
6139  CVE-2002-1757  Candidate  PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms".  Assigned (20050621)  None (candidate not yet proposed)    View
71675  CVE-2014-4379  Candidate  An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, which allows attackers to bypass the ASLR protection mechanism via a crafted application.  Assigned (20140620)  None (candidate not yet proposed)    View

Page 20527 of 20943, showing 5 records out of 104715 total, starting on record 102631, ending on 102635

Actions