CVE List

Id CVE No. Status Description Phase Votes Comments Actions
75032  CVE-2014-7731  Candidate  The Radio de la Cato (aka com.radio.de.la.cato) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9752  CVE-2004-1324  Candidate  The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.  Assigned (20050106)  None (candidate not yet proposed)    View
75288  CVE-2014-7987  Candidate  Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.  Assigned (20141008)  None (candidate not yet proposed)    View
10008  CVE-2004-1580  Candidate  SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.  Assigned (20050220)  None (candidate not yet proposed)    View
75544  CVE-2014-8243  Candidate  Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain the administrator"s MD5 password hash via a direct request for the /.htpasswd URI.  Assigned (20141012)  None (candidate not yet proposed)    View

Page 1922 of 20943, showing 5 records out of 104715 total, starting on record 9606, ending on 9610

Actions