CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9190  CVE-2004-0762  Candidate  Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.  Assigned (20040802)  None (candidate not yet proposed)    View
74726  CVE-2014-7425  Candidate  The Doodle Devil Free (aka com.joybits.doodledevil_free) application 2.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
74982  CVE-2014-7681  Candidate  The VMware vForums 2014 (aka com.coreapps.android.followme.vmwarevforums) application 6.0.9.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9702  CVE-2004-1274  Candidate  The DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters.  Assigned (20041220)  None (candidate not yet proposed)    View
75238  CVE-2014-7937  Candidate  Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Vorbis I data.  Assigned (20141006)  None (candidate not yet proposed)    View

Page 18872 of 20943, showing 5 records out of 104715 total, starting on record 94356, ending on 94360

Actions