CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8965  CVE-2004-0537  Candidate  Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.  Assigned (20040604)  None (candidate not yet proposed)    View
74501  CVE-2014-7201  Candidate  Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via the (1) education, (2) region, or (3) sector fields, as demonstrated by the tx_dmmjobcontrol_pi1[search][sector][] parameter to jobs/.  Assigned (20140926)  None (candidate not yet proposed)    View
9221  CVE-2004-0793  Candidate  The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.  Assigned (20040817)  None (candidate not yet proposed)    View
74757  CVE-2014-7456  Candidate  The Digit Magazine (aka com.magzter.digitmagazine) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9477  CVE-2004-1049  Candidate  Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."  Assigned (20041117)  None (candidate not yet proposed)    View

Page 417 of 20943, showing 5 records out of 104715 total, starting on record 2081, ending on 2085

Actions