CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9221  CVE-2004-0793  Candidate  The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.  Assigned (20040817)  None (candidate not yet proposed)    View
74757  CVE-2014-7456  Candidate  The Digit Magazine (aka com.magzter.digitmagazine) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9477  CVE-2004-1049  Candidate  Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."  Assigned (20041117)  None (candidate not yet proposed)    View
75013  CVE-2014-7712  Candidate  The Tiket.com Hotel & Flight (aka com.tiket.gits) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9733  CVE-2004-1305  Candidate  The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.  Assigned (20041221)  None (candidate not yet proposed)    View

Page 1023 of 20943, showing 5 records out of 104715 total, starting on record 5111, ending on 5115

Actions