CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
73211 | CVE-2014-5913 | Candidate | The Allies in War (aka com.gamelion.aiw) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140830) | None (candidate not yet proposed) | View | |
7931 | CVE-2003-1107 | Candidate | The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions. | Assigned (20050311) | None (candidate not yet proposed) | View | |
73467 | CVE-2014-6168 | Candidate | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | Assigned (20140902) | None (candidate not yet proposed) | View | |
8187 | CVE-2003-1363 | Candidate | The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection. | Assigned (20071016) | None (candidate not yet proposed) | View | |
73723 | CVE-2014-6423 | Candidate | The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line. | Assigned (20140916) | None (candidate not yet proposed) | View |
Page 20556 of 20943, showing 5 records out of 104715 total, starting on record 102776, ending on 102780