CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7405  CVE-2003-0578  Candidate  cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.  Assigned (20030716)  None (candidate not yet proposed)    View
72941  CVE-2014-5643  Candidate  The Instachat -Instagram Messenger (aka com.instachat.android) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7661  CVE-2003-0837  Candidate  Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.  Assigned (20030929)  None (candidate not yet proposed)    View
73197  CVE-2014-5899  Candidate  The Nespresso (aka com.nespresso.activities) application 2.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7917  CVE-2003-1093  Candidate  BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user"s password when it throws a ResourceAllocationException.  Assigned (20050310)  None (candidate not yet proposed)    View

Page 19060 of 20943, showing 5 records out of 104715 total, starting on record 95296, ending on 95300

Actions