CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73211  CVE-2014-5913  Candidate  The Allies in War (aka com.gamelion.aiw) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7931  CVE-2003-1107  Candidate  The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.  Assigned (20050311)  None (candidate not yet proposed)    View
73467  CVE-2014-6168  Candidate  Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.  Assigned (20140902)  None (candidate not yet proposed)    View
8187  CVE-2003-1363  Candidate  The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.  Assigned (20071016)  None (candidate not yet proposed)    View
73723  CVE-2014-6423  Candidate  The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line.  Assigned (20140916)  None (candidate not yet proposed)    View

Page 20553 of 20943, showing 5 records out of 104715 total, starting on record 102761, ending on 102765

Actions