CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72709  CVE-2014-5412  Candidate  Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.  Assigned (20140822)  None (candidate not yet proposed)    View
7429  CVE-2003-0602  Candidate  Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.  Assigned (20030725)  None (candidate not yet proposed)    View
72965  CVE-2014-5667  Candidate  The Vault-Hide SMS, Pics & Videos (aka com.netqin.ps) application 5.0.14.22 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7685  CVE-2003-0861  Candidate  Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.  Assigned (20031010)  None (candidate not yet proposed)    View
73221  CVE-2014-5922  Candidate  The ga6748 (aka com.g.ga6748) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 1020 of 20943, showing 5 records out of 104715 total, starting on record 5096, ending on 5100

Actions