CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74226  CVE-2014-6926  Candidate  The Allt om Brollop (aka com.paperton.wl.alltombrollop) application 1.53 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8946  CVE-2004-0518  Candidate  Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.  Assigned (20040601)  None (candidate not yet proposed)    View
74482  CVE-2014-7182  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.  Assigned (20140925)  None (candidate not yet proposed)    View
9202  CVE-2004-0774  Candidate  RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1.  Assigned (20040809)  None (candidate not yet proposed)    View
74738  CVE-2014-7437  Candidate  The Love Horoscope Guide (aka com.charl.charlylovehoroscopes) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 19837 of 20943, showing 5 records out of 104715 total, starting on record 99181, ending on 99185

Actions