CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73733  CVE-2014-6433  Candidate  gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.  Assigned (20140916)  None (candidate not yet proposed)    View
8453  CVE-2004-0025  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20040106)  None (candidate not yet proposed)    View
73989  CVE-2014-6689  Candidate  The JW Cards (aka com.jingwei.card) application 3.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8709  CVE-2004-0281  Candidate  Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
74245  CVE-2014-6945  Candidate  The Neeku Naaku Dash Dash (aka com.dakshaa.nndd) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 411 of 20943, showing 5 records out of 104715 total, starting on record 2051, ending on 2055

Actions