CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72947  CVE-2014-5649  Candidate  The iLove - Free Dating & Chat App (aka com.jestadigital.android.ilove) application 1.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7667  CVE-2003-0843  Candidate  Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.  Assigned (20031008)  None (candidate not yet proposed)    View
73203  CVE-2014-5905  Candidate  The Grocery List - Tomatoes (aka com.meucarrinho) application 5.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7923  CVE-2003-1099  Candidate  shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.  Assigned (20050311)  None (candidate not yet proposed)    View
73459  CVE-2014-6160  Candidate  IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.  Assigned (20140902)  None (candidate not yet proposed)    View

Page 18789 of 20943, showing 5 records out of 104715 total, starting on record 93941, ending on 93945

Actions