CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9215  CVE-2004-0787  Candidate  Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.  Assigned (20040817)  None (candidate not yet proposed)    View
74751  CVE-2014-7450  Candidate  The allnurses (aka com.tapatalk.allnursescom) application 3.4.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9471  CVE-2004-1043  Candidate  Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."  Assigned (20041117)  None (candidate not yet proposed)    View
75007  CVE-2014-7706  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141003)  None (candidate not yet proposed)    View
9727  CVE-2004-1299  Candidate  Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page.  Assigned (20041220)  None (candidate not yet proposed)    View

Page 20840 of 20943, showing 5 records out of 104715 total, starting on record 104196, ending on 104200

Actions