CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
71686 | CVE-2014-4390 | Candidate | Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application. | Assigned (20140620) | None (candidate not yet proposed) | View | |
6406 | CVE-2002-2024 | Candidate | Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71942 | CVE-2014-4645 | Candidate | Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link DSL-2760U-E1 allows remote attackers to inject arbitrary web script or HTML via a hostname. | Assigned (20140625) | None (candidate not yet proposed) | View | |
6662 | CVE-2002-2280 | Candidate | syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine"s IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server. | Assigned (20071017) | None (candidate not yet proposed) | View | |
72198 | CVE-2014-4901 | Candidate | The Bond Trading (aka com.appmakr.app613309) application 197705 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140710) | None (candidate not yet proposed) | View |
Page 493 of 20943, showing 5 records out of 104715 total, starting on record 2461, ending on 2465