CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71658  CVE-2014-4362  Candidate  The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app.  Assigned (20140620)  None (candidate not yet proposed)    View
6378  CVE-2002-1996  Candidate  Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.  Assigned (20050714)  None (candidate not yet proposed)    View
71914  CVE-2014-4617  Candidate  The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.  Assigned (20140624)  None (candidate not yet proposed)    View
6634  CVE-2002-2252  Candidate  SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.  Assigned (20071014)  None (candidate not yet proposed)    View
72170  CVE-2014-4873  Candidate  SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.  Assigned (20140710)  None (candidate not yet proposed)    View

Page 19189 of 20943, showing 5 records out of 104715 total, starting on record 95941, ending on 95945

Actions