CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73477  CVE-2014-6178  Candidate  Cross-site scripting (XSS) vulnerability in the widgets in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140902)  None (candidate not yet proposed)    View
8197  CVE-2003-1373  Candidate  Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.  Assigned (20071016)  None (candidate not yet proposed)    View
73733  CVE-2014-6433  Candidate  gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.  Assigned (20140916)  None (candidate not yet proposed)    View
8453  CVE-2004-0025  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20040106)  None (candidate not yet proposed)    View
73989  CVE-2014-6689  Candidate  The JW Cards (aka com.jingwei.card) application 3.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 432 of 20943, showing 5 records out of 104715 total, starting on record 2156, ending on 2160

Actions