CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72955  CVE-2014-5657  Candidate  The CA Lottery Results (aka com.matcho0.calotto) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7675  CVE-2003-0851  Candidate  OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.  Assigned (20031010)  None (candidate not yet proposed)    View
73211  CVE-2014-5913  Candidate  The Allies in War (aka com.gamelion.aiw) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7931  CVE-2003-1107  Candidate  The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.  Assigned (20050311)  None (candidate not yet proposed)    View
73467  CVE-2014-6168  Candidate  Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.  Assigned (20140902)  None (candidate not yet proposed)    View

Page 19945 of 20943, showing 5 records out of 104715 total, starting on record 99721, ending on 99725

Actions