CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
73477 | CVE-2014-6178 | Candidate | Cross-site scripting (XSS) vulnerability in the widgets in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20140902) | None (candidate not yet proposed) | View | |
8197 | CVE-2003-1373 | Candidate | Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php. | Assigned (20071016) | None (candidate not yet proposed) | View | |
73733 | CVE-2014-6433 | Candidate | gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action. | Assigned (20140916) | None (candidate not yet proposed) | View | |
8453 | CVE-2004-0025 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20040106) | None (candidate not yet proposed) | View | |
73989 | CVE-2014-6689 | Candidate | The JW Cards (aka com.jingwei.card) application 3.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View |
Page 432 of 20943, showing 5 records out of 104715 total, starting on record 2156, ending on 2160