CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73192  CVE-2014-5894  Candidate  The AireTalk: Text, Call, & More! (aka com.pingshow.amper) application 2.0.73 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7912  CVE-2003-1088  Candidate  Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.  Assigned (20050307)  None (candidate not yet proposed)    View
73448  CVE-2014-6149  Candidate  Directory traversal vulnerability in BIRT-viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to read arbitrary files via unspecified vectors.  Assigned (20140902)  None (candidate not yet proposed)    View
8168  CVE-2003-1344  Candidate  Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.  Assigned (20071014)  None (candidate not yet proposed)    View
73704  CVE-2014-6404  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140915)  None (candidate not yet proposed)    View

Page 19064 of 20943, showing 5 records out of 104715 total, starting on record 95316, ending on 95320

Actions