CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74759  CVE-2014-7458  Candidate  The BloomYou Valentine (aka com.bloomyouteam.bloomyou.valentine) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9479  CVE-2004-1051  Candidate  sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program"s full pathname.  Assigned (20041117)  None (candidate not yet proposed)    View
75015  CVE-2014-7714  Candidate  The ibon (aka tw.net.pic.mobi) application 3.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9735  CVE-2004-1307  Candidate  Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.  Assigned (20041221)  None (candidate not yet proposed)    View
75271  CVE-2014-7970  Candidate  The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.  Assigned (20141008)  None (candidate not yet proposed)    View

Page 573 of 20943, showing 5 records out of 104715 total, starting on record 2861, ending on 2865

Actions