CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6393 | CVE-2002-2011 | Candidate | Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71929 | CVE-2014-4632 | Candidate | VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate. | Assigned (20140624) | None (candidate not yet proposed) | View | |
6649 | CVE-2002-2267 | Candidate | bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file. | Assigned (20071017) | None (candidate not yet proposed) | View | |
72185 | CVE-2014-4888 | Candidate | The BattleFriends at Sea GOLD (aka com.tequilamobile.warshipslivegold) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140710) | None (candidate not yet proposed) | View | |
6905 | CVE-2003-0076 | Candidate | Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist. | Proposed (20030317) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | View |
Page 20391 of 20943, showing 5 records out of 104715 total, starting on record 101951, ending on 101955