CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74489  CVE-2014-7189  Candidate  crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.  Assigned (20140926)  None (candidate not yet proposed)    View
9209  CVE-2004-0781  Candidate  Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.  Assigned (20040817)  None (candidate not yet proposed)    View
74745  CVE-2014-7444  Candidate  The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9465  CVE-2004-1037  Candidate  The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.  Assigned (20041116)  None (candidate not yet proposed)    View
75001  CVE-2014-7700  Candidate  The Flying Fox (aka com.chillingo.slyfoxfree.android.aja) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 20398 of 20943, showing 5 records out of 104715 total, starting on record 101986, ending on 101990

Actions