CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72439  CVE-2014-5142  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140730)  None (candidate not yet proposed)    View
7159  CVE-2003-0331  Candidate  SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.  Assigned (20030520)  None (candidate not yet proposed)    View
72695  CVE-2014-5398  Candidate  Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.  Assigned (20140822)  None (candidate not yet proposed)    View
7415  CVE-2003-0588  Candidate  admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.  Assigned (20030717)  None (candidate not yet proposed)    View
72951  CVE-2014-5653  Candidate  The Unblock Me FREE (aka com.kiragames.unblockmefree) application 1.4.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 20231 of 20943, showing 5 records out of 104715 total, starting on record 101151, ending on 101155

Actions