CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73195  CVE-2014-5897  Candidate  The Parallel Mafia MMORPG (aka com.perblue.pm.client) application @7F070000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7915  CVE-2003-1091  Candidate  Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.  Assigned (20050310)  None (candidate not yet proposed)    View
73451  CVE-2014-6152  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Integrated Portal (TIP) 2.2.x allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140902)  None (candidate not yet proposed)    View
8171  CVE-2003-1347  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.  Assigned (20071014)  None (candidate not yet proposed)    View
73707  CVE-2014-6407  Candidate  Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.  Assigned (20140915)  None (candidate not yet proposed)    View

Page 19296 of 20943, showing 5 records out of 104715 total, starting on record 96476, ending on 96480

Actions