CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
71658 | CVE-2014-4362 | Candidate | The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app. | Assigned (20140620) | None (candidate not yet proposed) | View | |
6378 | CVE-2002-1996 | Candidate | Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71914 | CVE-2014-4617 | Candidate | The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence. | Assigned (20140624) | None (candidate not yet proposed) | View | |
6634 | CVE-2002-2252 | Candidate | SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter. | Assigned (20071014) | None (candidate not yet proposed) | View | |
72170 | CVE-2014-4873 | Candidate | SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data. | Assigned (20140710) | None (candidate not yet proposed) | View |
Page 19189 of 20943, showing 5 records out of 104715 total, starting on record 95941, ending on 95945