CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8700  CVE-2004-0272  Candidate  SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
74236  CVE-2014-6936  Candidate  The IDS 2013 (aka de.mobileeventguide.ids2013) application 1.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8956  CVE-2004-0528  Candidate  Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.  Assigned (20040603)  None (candidate not yet proposed)    View
74492  CVE-2014-7192  Candidate  Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.  Assigned (20140926)  None (candidate not yet proposed)    View
9212  CVE-2004-0784  Candidate  The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.  Assigned (20040817)  None (candidate not yet proposed)    View

Page 20637 of 20943, showing 5 records out of 104715 total, starting on record 103181, ending on 103185

Actions