CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73746  CVE-2014-6446  Candidate  The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.  Assigned (20140916)  None (candidate not yet proposed)    View
8466  CVE-2004-0038  Candidate  McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.  Assigned (20040107)  None (candidate not yet proposed)    View
74002  CVE-2014-6702  Candidate  The StarSat International (aka com.conduit.app_b15a1814d2d840198e70e3c235af5e8b.app) application 1.41.54.9222 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8722  CVE-2004-0294  Candidate  YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
74258  CVE-2014-6958  Candidate  The ISMRM-ESMRMB 2014 (aka com.coreapps.android.followme.ismrm_esmrmb14) application 6.0.8.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 1443 of 20943, showing 5 records out of 104715 total, starting on record 7211, ending on 7215

Actions