CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72440  CVE-2014-5143  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140730)  None (candidate not yet proposed)    View
7160  CVE-2003-0332  Candidate  The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.  Assigned (20030520)  None (candidate not yet proposed)    View
72696  CVE-2014-5399  Candidate  SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20140822)  None (candidate not yet proposed)    View
7416  CVE-2003-0589  Candidate  admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.  Assigned (20030717)  None (candidate not yet proposed)    View
72952  CVE-2014-5654  Candidate  The Kaspersky Internet Security (aka com.kms.free) application 11.4.4.232 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 19705 of 20943, showing 5 records out of 104715 total, starting on record 98521, ending on 98525

Actions