CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72725  CVE-2014-5428  Candidate  Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.  Assigned (20140822)  None (candidate not yet proposed)    View
7445  CVE-2003-0618  Candidate  Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.  Assigned (20030730)  None (candidate not yet proposed)    View
72981  CVE-2014-5683  Candidate  The Piano Teacher (aka com.rubycell.pianisthd) application 20140730 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7701  CVE-2003-0877  Candidate  Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.  Assigned (20031023)  None (candidate not yet proposed)    View
73237  CVE-2014-5938  Candidate  The AllDealsAsia All Deals ADA app (aka com.ada.deals) application 4.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 1680 of 20943, showing 5 records out of 104715 total, starting on record 8396, ending on 8400

Actions