CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72466  CVE-2014-5169  Candidate  Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title.  Assigned (20140731)  None (candidate not yet proposed)    View
7186  CVE-2003-0358  Candidate  Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.  Assigned (20030529)  None (candidate not yet proposed)    View
72722  CVE-2014-5425  Candidate  IOServer before Beta2112.exe allows remote attackers to cause a denial of service (out-of-bounds read and master entry consumption) via a null DNP3 header.  Assigned (20140822)  None (candidate not yet proposed)    View
7442  CVE-2003-0615  Candidate  Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form"s action parameter.  Assigned (20030730)  None (candidate not yet proposed)    View
72978  CVE-2014-5680  Candidate  The Tapatalk (aka com.quoord.tapatalkpro.activity) application 4.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 1441 of 20943, showing 5 records out of 104715 total, starting on record 7201, ending on 7205

Actions