CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73224  CVE-2014-5925  Candidate  The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7944  CVE-2003-1120  Candidate  Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server"s private key.  Assigned (20050311)  None (candidate not yet proposed)    View
73480  CVE-2014-6181  Candidate  IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 does not perform access-control checks for contained objects, which allows remote authenticated users to obtain sensitive information via unspecified vectors.  Assigned (20140902)  None (candidate not yet proposed)    View
8200  CVE-2003-1376  Candidate  WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.  Assigned (20071018)  None (candidate not yet proposed)    View
73736  CVE-2014-6436  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140916)  None (candidate not yet proposed)    View

Page 663 of 20943, showing 5 records out of 104715 total, starting on record 3311, ending on 3315

Actions