CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73970  CVE-2014-6670  Candidate  The SingaporeMotherhood Forum (aka com.tapatalk.singaporemotherhoodcomforum) application 3.6.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8690  CVE-2004-0262  Candidate  Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.  Modified (20050518)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
74226  CVE-2014-6926  Candidate  The Allt om Brollop (aka com.paperton.wl.alltombrollop) application 1.53 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8946  CVE-2004-0518  Candidate  Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.  Assigned (20040601)  None (candidate not yet proposed)    View
74482  CVE-2014-7182  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.  Assigned (20140925)  None (candidate not yet proposed)    View

Page 19841 of 20943, showing 5 records out of 104715 total, starting on record 99201, ending on 99205

Actions