CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72184  CVE-2014-4887  Candidate  The Joint Radio Blues (aka com.nobexinc.wls_69685189.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
72440  CVE-2014-5143  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140730)  None (candidate not yet proposed)    View
7160  CVE-2003-0332  Candidate  The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.  Assigned (20030520)  None (candidate not yet proposed)    View
72696  CVE-2014-5399  Candidate  SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20140822)  None (candidate not yet proposed)    View
7416  CVE-2003-0589  Candidate  admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.  Assigned (20030717)  None (candidate not yet proposed)    View

Page 20297 of 20943, showing 5 records out of 104715 total, starting on record 101481, ending on 101485

Actions