CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72950  CVE-2014-5652  Candidate  The Kicksend Photo Prints (aka com.kicksend.android.print) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7670  CVE-2003-0846  Candidate  SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.  Assigned (20031008)  None (candidate not yet proposed)    View
73206  CVE-2014-5908  Candidate  The Kmart (aka com.kmart.android) application @7F0C00EF for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7926  CVE-2003-1102  Candidate  Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.  Assigned (20050311)  None (candidate not yet proposed)    View
73462  CVE-2014-6163  Candidate  Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140902)  None (candidate not yet proposed)    View

Page 20152 of 20943, showing 5 records out of 104715 total, starting on record 100756, ending on 100760

Actions