CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71684  CVE-2014-4388  Candidate  IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4418.  Assigned (20140620)  None (candidate not yet proposed)    View
6404  CVE-2002-2022  Candidate  Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute.  Assigned (20050714)  None (candidate not yet proposed)    View
71940  CVE-2014-4643  Candidate  Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command.  Assigned (20140625)  None (candidate not yet proposed)    View
6660  CVE-2002-2278  Candidate  Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.  Assigned (20071017)  None (candidate not yet proposed)    View
72196  CVE-2014-4899  Candidate  The Indian Cement Review (aka com.magzter.indiancementreview) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View

Page 328 of 20943, showing 5 records out of 104715 total, starting on record 1636, ending on 1640

Actions