CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73206  CVE-2014-5908  Candidate  The Kmart (aka com.kmart.android) application @7F0C00EF for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7926  CVE-2003-1102  Candidate  Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.  Assigned (20050311)  None (candidate not yet proposed)    View
73462  CVE-2014-6163  Candidate  Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140902)  None (candidate not yet proposed)    View
8182  CVE-2003-1358  Candidate  rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.  Assigned (20071016)  None (candidate not yet proposed)    View
73718  CVE-2014-6418  Candidate  net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.  Assigned (20140915)  None (candidate not yet proposed)    View

Page 20158 of 20943, showing 5 records out of 104715 total, starting on record 100786, ending on 100790

Actions