CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73745  CVE-2014-6445  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.  Assigned (20140916)  None (candidate not yet proposed)    View
8465  CVE-2004-0037  Candidate  FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams  Williams> insufficient data.  View
74001  CVE-2014-6701  Candidate  The Vendormate Mobile (aka com.vendormate.mobile) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8721  CVE-2004-0293  Candidate  Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
74257  CVE-2014-6957  Candidate  The scottcolibmn (aka com.bredir.boopsie.scottlib) application 4.5.110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 1364 of 20943, showing 5 records out of 104715 total, starting on record 6816, ending on 6820

Actions