CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7412  CVE-2003-0585  Candidate  SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.  Assigned (20030717)  None (candidate not yet proposed)    View
72948  CVE-2014-5650  Candidate  The Traffic Jam Free (aka com.jiuzhangtech.rushhour) application 1.7.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7668  CVE-2003-0844  Candidate  mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.  Assigned (20031008)  None (candidate not yet proposed)    View
73204  CVE-2014-5906  Candidate  The Lil Wayne Slots: FREE SLOTS (aka com.lilwayneslots.slots.android) application 1.138 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7924  CVE-2003-1100  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.  Assigned (20050311)  None (candidate not yet proposed)    View

Page 19992 of 20943, showing 5 records out of 104715 total, starting on record 99956, ending on 99960

Actions