CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73989  CVE-2014-6689  Candidate  The JW Cards (aka com.jingwei.card) application 3.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8709  CVE-2004-0281  Candidate  Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
74245  CVE-2014-6945  Candidate  The Neeku Naaku Dash Dash (aka com.dakshaa.nndd) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8965  CVE-2004-0537  Candidate  Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.  Assigned (20040604)  None (candidate not yet proposed)    View
74501  CVE-2014-7201  Candidate  Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via the (1) education, (2) region, or (3) sector fields, as demonstrated by the tx_dmmjobcontrol_pi1[search][sector][] parameter to jobs/.  Assigned (20140926)  None (candidate not yet proposed)    View

Page 1022 of 20943, showing 5 records out of 104715 total, starting on record 5106, ending on 5110

Actions