CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73452  CVE-2014-6153  Candidate  The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.  Assigned (20140902)  None (candidate not yet proposed)    View
8172  CVE-2003-1348  Candidate  Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.  Assigned (20071014)  None (candidate not yet proposed)    View
73708  CVE-2014-6408  Candidate  Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.  Assigned (20140915)  None (candidate not yet proposed)    View
8428  CVE-2003-1604  Candidate  The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a related issue to CVE-2015-8787.  Assigned (20160127)  None (candidate not yet proposed)    View
73964  CVE-2014-6664  Candidate  The Latin Angels Music HD (aka com.applizards.lafreetj) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 19363 of 20943, showing 5 records out of 104715 total, starting on record 96811, ending on 96815

Actions