CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
72434 | CVE-2014-5137 | Candidate | Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule. | Assigned (20140730) | None (candidate not yet proposed) | View | |
7154 | CVE-2003-0326 | Candidate | Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc. | Assigned (20030519) | None (candidate not yet proposed) | View | |
72690 | CVE-2014-5393 | Candidate | Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors. | Assigned (20140822) | None (candidate not yet proposed) | View | |
7410 | CVE-2003-0583 | Candidate | Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument. | Assigned (20030717) | None (candidate not yet proposed) | View | |
72946 | CVE-2014-5648 | Candidate | The Chat, Flirt & Dating Heart JAUMO (aka com.jaumo) application 2.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140830) | None (candidate not yet proposed) | View |
Page 19228 of 20943, showing 5 records out of 104715 total, starting on record 96136, ending on 96140