CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
73958 | CVE-2014-6658 | Candidate | The Apploi Job Search- Find Jobs (aka com.apploi) application 4.19 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View | |
8678 | CVE-2004-0250 | Candidate | SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php. | Proposed (20040318) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
74214 | CVE-2014-6914 | Candidate | The Houcine El Jasmi (aka com.devkhr31.houcineeljasmi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View | |
8934 | CVE-2004-0506 | Candidate | The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference. | Assigned (20040601) | None (candidate not yet proposed) | View | |
74470 | CVE-2014-7170 | Candidate | Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service. | Assigned (20140925) | None (candidate not yet proposed) | View |
Page 18886 of 20943, showing 5 records out of 104715 total, starting on record 94426, ending on 94430