CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7178  CVE-2003-0350  Candidate  The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.  Assigned (20030528)  None (candidate not yet proposed)    View
72714  CVE-2014-5417  Candidate  Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140822)  None (candidate not yet proposed)    View
7434  CVE-2003-0607  Candidate  Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.  Assigned (20030728)  None (candidate not yet proposed)    View
72970  CVE-2014-5672  Candidate  The NQ Mobile Security & Antivirus (aka com.nqmobile.antivirus20) application 7.2.16.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7690  CVE-2003-0866  Candidate  The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.  Assigned (20031015)  None (candidate not yet proposed)    View

Page 1419 of 20943, showing 5 records out of 104715 total, starting on record 7091, ending on 7095

Actions