CVE List

Id CVE No. Status Description Phase Votes Comments Actions
75025  CVE-2014-7724  Candidate  The Chemssou Blink (aka com.chemssou.blink) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9745  CVE-2004-1317  Candidate  Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.  Assigned (20041230)  None (candidate not yet proposed)    View
75281  CVE-2014-7980  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings.  Assigned (20141008)  None (candidate not yet proposed)    View
10001  CVE-2004-1573  Candidate  The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.  Assigned (20050220)  None (candidate not yet proposed)    View
75537  CVE-2014-8236  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141010)  None (candidate not yet proposed)    View

Page 1366 of 20943, showing 5 records out of 104715 total, starting on record 6826, ending on 6830

Actions