CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73216  CVE-2014-5917  Candidate  The Slideshow 365 (aka com.Slideshow) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7936  CVE-2003-1112  Candidate  The Session Initiation Protocol (SIP) implementation in Ingate Firewall and Ingate SIParator before 3.1.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.  Assigned (20050311)  None (candidate not yet proposed)    View
73472  CVE-2014-6173  Candidate  Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140902)  None (candidate not yet proposed)    View
8192  CVE-2003-1368  Candidate  Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.  Assigned (20071016)  None (candidate not yet proposed)    View
73728  CVE-2014-6428  Candidate  The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not initialize a certain ID value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.  Assigned (20140916)  None (candidate not yet proposed)    View

Page 11 of 20943, showing 5 records out of 104715 total, starting on record 51, ending on 55

<<first 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 last>>

Actions