CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74492  CVE-2014-7192  Candidate  Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.  Assigned (20140926)  None (candidate not yet proposed)    View
9212  CVE-2004-0784  Candidate  The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.  Assigned (20040817)  None (candidate not yet proposed)    View
74748  CVE-2014-7447  Candidate  The Dattch - The Lesbian App (aka com.dattch.dattch.app) application 0.30 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9468  CVE-2004-1040  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20041117)  None (candidate not yet proposed)    View
75004  CVE-2014-7703  Candidate  The Terrorizer Magazine (aka com.triactivemedia.terrorizer) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 20027 of 20943, showing 5 records out of 104715 total, starting on record 100131, ending on 100135

Actions