CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72697  CVE-2014-5400  Candidate  The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.  Assigned (20140822)  None (candidate not yet proposed)    View
7417  CVE-2003-0590  Candidate  Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.  Assigned (20030717)  None (candidate not yet proposed)    View
72953  CVE-2014-5655  Candidate  The CM Browser - Fast & Secure (aka com.ksmobile.cb) application 5.0.50 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7673  CVE-2003-0849  Candidate  Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.  Assigned (20031008)  None (candidate not yet proposed)    View
73209  CVE-2014-5911  Candidate  The Free App Icons & Icon Packs (aka com.jellytap.cooliconfinder) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 20375 of 20943, showing 5 records out of 104715 total, starting on record 101871, ending on 101875

Actions