CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74503  CVE-2014-7203  Candidate  libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.  Assigned (20140926)  None (candidate not yet proposed)    View
9223  CVE-2004-0795  Candidate  DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.  Assigned (20040819)  None (candidate not yet proposed)    View
74759  CVE-2014-7458  Candidate  The BloomYou Valentine (aka com.bloomyouteam.bloomyou.valentine) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9479  CVE-2004-1051  Candidate  sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program"s full pathname.  Assigned (20041117)  None (candidate not yet proposed)    View
75015  CVE-2014-7714  Candidate  The ibon (aka tw.net.pic.mobi) application 3.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 1711 of 20943, showing 5 records out of 104715 total, starting on record 8551, ending on 8555

Actions