CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73979  CVE-2014-6679  Candidate  The wEPISDParentPortal (aka com.dreamstep.wEPISDParentPortal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8699  CVE-2004-0271  Candidate  Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
74235  CVE-2014-6935  Candidate  The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8955  CVE-2004-0527  Candidate  KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.  Assigned (20040603)  None (candidate not yet proposed)    View
74491  CVE-2014-7191  Candidate  The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.  Assigned (20140926)  None (candidate not yet proposed)    View

Page 20557 of 20943, showing 5 records out of 104715 total, starting on record 102781, ending on 102785

Actions