CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68094  CVE-2014-0685  Candidate  Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2) IGMPv3 packets, aka Bug ID CSCug61691.  Assigned (20140102)  None (candidate not yet proposed)    View
2814  CVE-2000-1247  Candidate  The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.  Assigned (20111004)  None (candidate not yet proposed)    View
68350  CVE-2014-0941  Candidate  Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0942.  Assigned (20140106)  None (candidate not yet proposed)    View
68606  CVE-2014-1311  Candidate  WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.  Assigned (20140108)  None (candidate not yet proposed)    View
68862  CVE-2014-1567  Candidate  Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.  Assigned (20140116)  None (candidate not yet proposed)    View

Page 20755 of 20943, showing 5 records out of 104715 total, starting on record 103771, ending on 103775

Actions