CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73454  CVE-2014-6155  Candidate  Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files via unspecified vectors.  Assigned (20140902)  None (candidate not yet proposed)    View
8174  CVE-2003-1350  Candidate  List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.  Assigned (20071014)  None (candidate not yet proposed)    View
73710  CVE-2014-6410  Candidate  The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.  Assigned (20140915)  None (candidate not yet proposed)    View
73966  CVE-2014-6666  Candidate  The Baglamukhi (aka com.wshribaglamukhiblog) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
74222  CVE-2014-6922  Candidate  The KFAI Community Radio (aka com.skyblue.pra.kfai) application 2.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 19528 of 20943, showing 5 records out of 104715 total, starting on record 97636, ending on 97640

Actions