CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9186  CVE-2004-0758  Candidate  Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.  Assigned (20040802)  None (candidate not yet proposed)    View
74722  CVE-2014-7421  Candidate  The Revel in the Rideau Lakes (aka com.mytoursapp.android.app326) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9442  CVE-2004-1014  Candidate  statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.  Assigned (20041104)  None (candidate not yet proposed)    View
74978  CVE-2014-7677  Candidate  The Scudetto (aka com.scudetto) application 2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9698  CVE-2004-1270  Candidate  lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.  Assigned (20041220)  None (candidate not yet proposed)    View

Page 18603 of 20943, showing 5 records out of 104715 total, starting on record 93011, ending on 93015

Actions