CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6393  CVE-2002-2011  Candidate  Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter.  Assigned (20050714)  None (candidate not yet proposed)    View
71929  CVE-2014-4632  Candidate  VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.  Assigned (20140624)  None (candidate not yet proposed)    View
6649  CVE-2002-2267  Candidate  bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file.  Assigned (20071017)  None (candidate not yet proposed)    View
72185  CVE-2014-4888  Candidate  The BattleFriends at Sea GOLD (aka com.tequilamobile.warshipslivegold) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
6905  CVE-2003-0076  Candidate  Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall    View

Page 20391 of 20943, showing 5 records out of 104715 total, starting on record 101951, ending on 101955

Actions