CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74507  CVE-2014-7206  Candidate  The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.  Assigned (20140927)  None (candidate not yet proposed)    View
9227  CVE-2004-0799  Candidate  The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".  Assigned (20040824)  None (candidate not yet proposed)    View
74763  CVE-2014-7462  Candidate  The Fashion Story: Neon 90"s (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9483  CVE-2004-1055  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.  Assigned (20041119)  None (candidate not yet proposed)    View
75019  CVE-2014-7718  Candidate  The Travel+Leisure (aka com.magzter.travelleisure) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 1501 of 20943, showing 5 records out of 104715 total, starting on record 7501, ending on 7505

Actions