CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74224  CVE-2014-6924  Candidate  The Metro News (aka com.netpia.ha.metro) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8944  CVE-2004-0516  Candidate  Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.  Assigned (20040601)  None (candidate not yet proposed)    View
74480  CVE-2014-7180  Candidate  Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.  Assigned (20140925)  None (candidate not yet proposed)    View
9200  CVE-2004-0772  Candidate  Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.  Assigned (20040805)  None (candidate not yet proposed)    View
74736  CVE-2014-7435  Candidate  The AJD Bail Bonds (aka com.onesolutionapps.ajdbailbondsandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 19674 of 20943, showing 5 records out of 104715 total, starting on record 98366, ending on 98370

Actions