CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8695 | CVE-2004-0267 | Candidate | The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp. | Modified (20050518) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
74231 | CVE-2014-6931 | Candidate | The Treves Dance Center (aka com.myapphone.android.myapptrvesdancecenter) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View | |
8951 | CVE-2004-0523 | Candidate | Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root. | Assigned (20040603) | None (candidate not yet proposed) | View | |
74487 | CVE-2014-7187 | Candidate | Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue. | Assigned (20140925) | None (candidate not yet proposed) | View | |
9207 | CVE-2004-0779 | Candidate | The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site. | Assigned (20040813) | None (candidate not yet proposed) | View |
Page 20239 of 20943, showing 5 records out of 104715 total, starting on record 101191, ending on 101195