CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72722  CVE-2014-5425  Candidate  IOServer before Beta2112.exe allows remote attackers to cause a denial of service (out-of-bounds read and master entry consumption) via a null DNP3 header.  Assigned (20140822)  None (candidate not yet proposed)    View
7442  CVE-2003-0615  Candidate  Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form"s action parameter.  Assigned (20030730)  None (candidate not yet proposed)    View
72978  CVE-2014-5680  Candidate  The Tapatalk (aka com.quoord.tapatalkpro.activity) application 4.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7698  CVE-2003-0874  Candidate  Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.  Assigned (20031021)  None (candidate not yet proposed)    View
73234  CVE-2014-5935  Candidate  The Daily Free App @ Amazon (aka com.kattanweb.android.dfaa) application 1.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 1431 of 20943, showing 5 records out of 104715 total, starting on record 7151, ending on 7155

Actions