CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
71933 | CVE-2014-4636 | Candidate | Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to hijack the authentication of arbitrary users for requests that perform Docbase operations. | Assigned (20140624) | None (candidate not yet proposed) | View | |
6653 | CVE-2002-2271 | Candidate | Buffer overflow in BigFun 1.51b IRC client, when the Direct Client Connection (DCC) option is used, allows remote attackers to cause a denial of service (crash) via a long string. | Assigned (20071017) | None (candidate not yet proposed) | View | |
72189 | CVE-2014-4892 | Candidate | The uControl Smart Home Automation (aka de.ucontrol) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140710) | None (candidate not yet proposed) | View | |
6909 | CVE-2003-0080 | Candidate | The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled. | Assigned (20030210) | None (candidate not yet proposed) | View | |
72445 | CVE-2014-5148 | Candidate | Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process. | Assigned (20140730) | None (candidate not yet proposed) | View |
Page 20713 of 20943, showing 5 records out of 104715 total, starting on record 103561, ending on 103565