CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8695  CVE-2004-0267  Candidate  The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
74231  CVE-2014-6931  Candidate  The Treves Dance Center (aka com.myapphone.android.myapptrvesdancecenter) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8951  CVE-2004-0523  Candidate  Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.  Assigned (20040603)  None (candidate not yet proposed)    View
74487  CVE-2014-7187  Candidate  Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.  Assigned (20140925)  None (candidate not yet proposed)    View
9207  CVE-2004-0779  Candidate  The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.  Assigned (20040813)  None (candidate not yet proposed)    View

Page 20239 of 20943, showing 5 records out of 104715 total, starting on record 101191, ending on 101195

Actions