CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
72708 | CVE-2014-5411 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20140822) | None (candidate not yet proposed) | View | |
7428 | CVE-2003-0601 | Candidate | Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved. | Assigned (20030723) | None (candidate not yet proposed) | View | |
72964 | CVE-2014-5666 | Candidate | The AVD Download Video (aka com.myboyfriendisageek.videocatcher.demo) application 3.3.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140830) | None (candidate not yet proposed) | View | |
7684 | CVE-2003-0860 | Candidate | Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors. | Assigned (20031010) | None (candidate not yet proposed) | View | |
73220 | CVE-2014-5921 | Candidate | The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140830) | None (candidate not yet proposed) | View |
Page 334 of 20943, showing 5 records out of 104715 total, starting on record 1666, ending on 1670