CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72188  CVE-2014-4891  Candidate  The CT iHub (aka com.concursive.ctihub) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
72444  CVE-2014-5147  Candidate  Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.  Assigned (20140730)  None (candidate not yet proposed)    View
7164  CVE-2003-0336  Candidate  Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachment Converted:" string, which is not properly handled by Eudora.  Assigned (20030522)  None (candidate not yet proposed)    View
72700  CVE-2014-5403  Candidate  Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.  Assigned (20140822)  None (candidate not yet proposed)    View
72956  CVE-2014-5658  Candidate  The MercadoLibre (aka com.mercadolibre) application 3.8.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 19482 of 20943, showing 5 records out of 104715 total, starting on record 97406, ending on 97410

Actions