CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72469  CVE-2014-5172  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140731)  None (candidate not yet proposed)    View
7189  CVE-2003-0361  Candidate  gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.  Assigned (20030529)  None (candidate not yet proposed)    View
72725  CVE-2014-5428  Candidate  Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.  Assigned (20140822)  None (candidate not yet proposed)    View
7445  CVE-2003-0618  Candidate  Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.  Assigned (20030730)  None (candidate not yet proposed)    View
72981  CVE-2014-5683  Candidate  The Piano Teacher (aka com.rubycell.pianisthd) application 20140730 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 1661 of 20943, showing 5 records out of 104715 total, starting on record 8301, ending on 8305

Actions