CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
72964 | CVE-2014-5666 | Candidate | The AVD Download Video (aka com.myboyfriendisageek.videocatcher.demo) application 3.3.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140830) | None (candidate not yet proposed) | View | |
7684 | CVE-2003-0860 | Candidate | Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors. | Assigned (20031010) | None (candidate not yet proposed) | View | |
73220 | CVE-2014-5921 | Candidate | The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140830) | None (candidate not yet proposed) | View | |
7940 | CVE-2003-1116 | Candidate | The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener. | Assigned (20050311) | None (candidate not yet proposed) | View | |
73476 | CVE-2014-6177 | Candidate | IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.3 does not perform access-control checks for depth-0 retrieve operations, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | Assigned (20140902) | None (candidate not yet proposed) | View |
Page 354 of 20943, showing 5 records out of 104715 total, starting on record 1766, ending on 1770