CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74233  CVE-2014-6933  Candidate  The Toraware Takojyou (aka ltd.pte.wavea.torawaretakojyou) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8953  CVE-2004-0525  Candidate  HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero.  Assigned (20040603)  None (candidate not yet proposed)    View
74489  CVE-2014-7189  Candidate  crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.  Assigned (20140926)  None (candidate not yet proposed)    View
9209  CVE-2004-0781  Candidate  Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.  Assigned (20040817)  None (candidate not yet proposed)    View
74745  CVE-2014-7444  Candidate  The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 20377 of 20943, showing 5 records out of 104715 total, starting on record 101881, ending on 101885

Actions