CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74477  CVE-2014-7177  Candidate  XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.  Assigned (20140925)  None (candidate not yet proposed)    View
9197  CVE-2004-0769  Candidate  Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than CVE-2004-0771.  Assigned (20040803)  None (candidate not yet proposed)    View
74733  CVE-2014-7432  Candidate  The CalculatorApp (aka com.intuit.alm.testandroidapp) application 4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9453  CVE-2004-1025  Candidate  Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.  Assigned (20041112)  None (candidate not yet proposed)    View
74989  CVE-2014-7688  Candidate  The Home Improvement (aka com.whomeimprovementapp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 19452 of 20943, showing 5 records out of 104715 total, starting on record 97256, ending on 97260

Actions