CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72979  CVE-2014-5681  Candidate  The XDA-Developers (aka com.quoord.tapatalkxda.activity) application 3.9.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7699  CVE-2003-0875  Candidate  Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.  Assigned (20031023)  None (candidate not yet proposed)    View
73235  CVE-2014-5936  Candidate  The INCOgnito Private Browser (aka com.SL.InCoBrowser) application 1.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7955  CVE-2003-1131  Candidate  PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.  Assigned (20050320)  None (candidate not yet proposed)    View
73491  CVE-2014-6192  Candidate  Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140902)  None (candidate not yet proposed)    View

Page 1521 of 20943, showing 5 records out of 104715 total, starting on record 7601, ending on 7605

Actions