CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72708  CVE-2014-5411  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140822)  None (candidate not yet proposed)    View
7428  CVE-2003-0601  Candidate  Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.  Assigned (20030723)  None (candidate not yet proposed)    View
72964  CVE-2014-5666  Candidate  The AVD Download Video (aka com.myboyfriendisageek.videocatcher.demo) application 3.3.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7684  CVE-2003-0860  Candidate  Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.  Assigned (20031010)  None (candidate not yet proposed)    View
73220  CVE-2014-5921  Candidate  The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 334 of 20943, showing 5 records out of 104715 total, starting on record 1666, ending on 1670

Actions