CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72434  CVE-2014-5137  Candidate  Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.  Assigned (20140730)  None (candidate not yet proposed)    View
7154  CVE-2003-0326  Candidate  Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.  Assigned (20030519)  None (candidate not yet proposed)    View
72690  CVE-2014-5393  Candidate  Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors.  Assigned (20140822)  None (candidate not yet proposed)    View
7410  CVE-2003-0583  Candidate  Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.  Assigned (20030717)  None (candidate not yet proposed)    View
72946  CVE-2014-5648  Candidate  The Chat, Flirt & Dating Heart JAUMO (aka com.jaumo) application 2.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 19228 of 20943, showing 5 records out of 104715 total, starting on record 96136, ending on 96140

Actions