CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72696  CVE-2014-5399  Candidate  SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20140822)  None (candidate not yet proposed)    View
7416  CVE-2003-0589  Candidate  admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.  Assigned (20030717)  None (candidate not yet proposed)    View
72952  CVE-2014-5654  Candidate  The Kaspersky Internet Security (aka com.kms.free) application 11.4.4.232 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7672  CVE-2003-0848  Candidate  Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.  Assigned (20031008)  None (candidate not yet proposed)    View
73208  CVE-2014-5910  Candidate  The Dog Whistle (aka com.dogwhistle.dogtrainingandroidapp) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 20312 of 20943, showing 5 records out of 104715 total, starting on record 101556, ending on 101560

Actions