CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
72466 | CVE-2014-5169 | Candidate | Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title. | Assigned (20140731) | None (candidate not yet proposed) | View | |
7186 | CVE-2003-0358 | Candidate | Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option. | Assigned (20030529) | None (candidate not yet proposed) | View | |
72722 | CVE-2014-5425 | Candidate | IOServer before Beta2112.exe allows remote attackers to cause a denial of service (out-of-bounds read and master entry consumption) via a null DNP3 header. | Assigned (20140822) | None (candidate not yet proposed) | View | |
7442 | CVE-2003-0615 | Candidate | Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form"s action parameter. | Assigned (20030730) | None (candidate not yet proposed) | View | |
72978 | CVE-2014-5680 | Candidate | The Tapatalk (aka com.quoord.tapatalkpro.activity) application 4.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140830) | None (candidate not yet proposed) | View |
Page 1441 of 20943, showing 5 records out of 104715 total, starting on record 7201, ending on 7205