CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74506  CVE-2014-7205  Candidate  Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.  Assigned (20140927)  None (candidate not yet proposed)    View
9226  CVE-2004-0798  Candidate  Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.  Assigned (20040824)  None (candidate not yet proposed)    View
74762  CVE-2014-7461  Candidate  The A King Sperm by Dr. Seema Rao (aka com.wKingSperm) application 0.63.13384.23020 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9482  CVE-2004-1054  Candidate  Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.  Assigned (20041118)  None (candidate not yet proposed)    View
75018  CVE-2014-7717  Candidate  The Mills-Hazel Property Mgmt (aka com.appexpress.millshazelpropertymanagement) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 1422 of 20943, showing 5 records out of 104715 total, starting on record 7106, ending on 7110

Actions