CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8700 | CVE-2004-0272 | Candidate | SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
74236 | CVE-2014-6936 | Candidate | The IDS 2013 (aka de.mobileeventguide.ids2013) application 1.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View | |
8956 | CVE-2004-0528 | Candidate | Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack. | Assigned (20040603) | None (candidate not yet proposed) | View | |
74492 | CVE-2014-7192 | Candidate | Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file. | Assigned (20140926) | None (candidate not yet proposed) | View | |
9212 | CVE-2004-0784 | Candidate | The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector. | Assigned (20040817) | None (candidate not yet proposed) | View |
Page 20637 of 20943, showing 5 records out of 104715 total, starting on record 103181, ending on 103185