CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6410  CVE-2002-2028  Candidate  The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.  Assigned (20050714)  None (candidate not yet proposed)    View
71946  CVE-2014-4649  Candidate  SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.  Assigned (20140625)  None (candidate not yet proposed)    View
6666  CVE-2002-2284  Candidate  Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.  Assigned (20071017)  None (candidate not yet proposed)    View
72202  CVE-2014-4905  Candidate  The Clean Internet Browser (aka com.cleantab.browsesecure) application 1.36 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
72458  CVE-2014-5161  Candidate  The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip " " characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.  Assigned (20140731)  None (candidate not yet proposed)    View

Page 1418 of 20943, showing 5 records out of 104715 total, starting on record 7086, ending on 7090

Actions