CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8445 | CVE-2004-0017 | Candidate | Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations. | Modified (20071113) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall | Williams> i believe this affects phpGroupWare 0.9.14.006 and earlier, and phpGroupWare 0.9.16RC1 and earlier. | http://phpgroupware.org/downloads | View |
73981 | CVE-2014-6681 | Candidate | The Mahabharata Audiocast (aka com.wordbox.mahabharataAudiocast) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View | |
74237 | CVE-2014-6937 | Candidate | The China CITIC Bank Credit Card (aka com.citiccard.mobilebank) application 3.3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View | |
8957 | CVE-2004-0529 | Candidate | The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490. | Assigned (20040603) | None (candidate not yet proposed) | View | |
74493 | CVE-2014-7193 | Candidate | The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site that is visited by an application consumer. | Assigned (20140926) | None (candidate not yet proposed) | View |
Page 20716 of 20943, showing 5 records out of 104715 total, starting on record 103576, ending on 103580