CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6642  CVE-2002-2260  Candidate  Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.  Assigned (20071017)  None (candidate not yet proposed)    View
72178  CVE-2014-4881  Candidate  The PartyTrack library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
6898  CVE-2003-0069  Entry  The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user"s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.        View
72434  CVE-2014-5137  Candidate  Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.  Assigned (20140730)  None (candidate not yet proposed)    View
7154  CVE-2003-0326  Candidate  Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.  Assigned (20030519)  None (candidate not yet proposed)    View

Page 19831 of 20943, showing 5 records out of 104715 total, starting on record 99151, ending on 99155

Actions