CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74238  CVE-2014-6938  Candidate  The Apostilas musicais (aka com.apostilas) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8958  CVE-2004-0530  Candidate  The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.  Assigned (20040604)  None (candidate not yet proposed)    View
74494  CVE-2014-7194  Candidate  TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before 1.1.1 allow remote attackers to obtain sensitive information or modify data by leveraging agent access.  Assigned (20140926)  None (candidate not yet proposed)    View
9214  CVE-2004-0786  Candidate  The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.  Assigned (20040817)  None (candidate not yet proposed)    View
74750  CVE-2014-7449  Candidate  The My NGEMC Account (aka com.ngemc.smartapps) application 1.153.0034 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 20795 of 20943, showing 5 records out of 104715 total, starting on record 103971, ending on 103975

Actions