CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72946  CVE-2014-5648  Candidate  The Chat, Flirt & Dating Heart JAUMO (aka com.jaumo) application 2.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7666  CVE-2003-0842  Candidate  Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.  Assigned (20031008)  None (candidate not yet proposed)    View
73202  CVE-2014-5904  Candidate  The MiniInTheBox Online Shopping (aka com.miniinthebox.android) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7922  CVE-2003-1098  Candidate  The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.  Assigned (20050311)  None (candidate not yet proposed)    View
73458  CVE-2014-6159  Candidate  IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.  Assigned (20140902)  None (candidate not yet proposed)    View

Page 18712 of 20943, showing 5 records out of 104715 total, starting on record 93556, ending on 93560

Actions