CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68860  CVE-2014-1565  Candidate  The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 does not properly create audio timelines, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted API calls.  Assigned (20140116)  None (candidate not yet proposed)    View
69116  CVE-2014-1821  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140129)  None (candidate not yet proposed)    View
69372  CVE-2014-2077  Candidate  Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving "the aria "tags" for screenreaders at the top bar".  Assigned (20140219)  None (candidate not yet proposed)    View
69628  CVE-2014-2333  Candidate  Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.  Assigned (20140312)  None (candidate not yet proposed)    View
4348  CVE-2001-1548  Candidate  ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 20602 of 20943, showing 5 records out of 104715 total, starting on record 103006, ending on 103010

Actions