CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73958  CVE-2014-6658  Candidate  The Apploi Job Search- Find Jobs (aka com.apploi) application 4.19 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8678  CVE-2004-0250  Candidate  SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
74214  CVE-2014-6914  Candidate  The Houcine El Jasmi (aka com.devkhr31.houcineeljasmi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8934  CVE-2004-0506  Candidate  The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.  Assigned (20040601)  None (candidate not yet proposed)    View
74470  CVE-2014-7170  Candidate  Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.  Assigned (20140925)  None (candidate not yet proposed)    View

Page 18886 of 20943, showing 5 records out of 104715 total, starting on record 94426, ending on 94430

Actions