CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7930 | CVE-2003-1106 | Candidate | The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute. | Assigned (20050311) | None (candidate not yet proposed) | View | |
73466 | CVE-2014-6167 | Candidate | Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | Assigned (20140902) | None (candidate not yet proposed) | View | |
8186 | CVE-2003-1362 | Candidate | Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases. | Assigned (20071016) | None (candidate not yet proposed) | View | |
73722 | CVE-2014-6422 | Candidate | The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtables for a media channel, which allows remote attackers to cause a denial of service (application crash) via a crafted packet to the RTP dissector. | Assigned (20140916) | None (candidate not yet proposed) | View | |
73978 | CVE-2014-6678 | Candidate | The Algeria Radio (aka com.wordbox.algeriaRadio) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View |
Page 20453 of 20943, showing 5 records out of 104715 total, starting on record 102261, ending on 102265