CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72198  CVE-2014-4901  Candidate  The Bond Trading (aka com.appmakr.app613309) application 197705 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
6918  CVE-2003-0089  Candidate  Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.  Assigned (20030211)  None (candidate not yet proposed)    View
72454  CVE-2014-5157  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5196. Reason: This candidate is a reservation duplicate of CVE-2014-5196. Notes: All CVE users should reference CVE-2014-5196 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20140731)  None (candidate not yet proposed)    View
7174  CVE-2003-0346  Candidate  Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.  Assigned (20030528)  None (candidate not yet proposed)    View
72710  CVE-2014-5413  Candidate  Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.  Assigned (20140822)  None (candidate not yet proposed)    View

Page 1100 of 20943, showing 5 records out of 104715 total, starting on record 5496, ending on 5500

Actions