CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71946  CVE-2014-4649  Candidate  SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.  Assigned (20140625)  None (candidate not yet proposed)    View
6666  CVE-2002-2284  Candidate  Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.  Assigned (20071017)  None (candidate not yet proposed)    View
72202  CVE-2014-4905  Candidate  The Clean Internet Browser (aka com.cleantab.browsesecure) application 1.36 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
72458  CVE-2014-5161  Candidate  The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip " " characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.  Assigned (20140731)  None (candidate not yet proposed)    View
7178  CVE-2003-0350  Candidate  The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.  Assigned (20030528)  None (candidate not yet proposed)    View

Page 815 of 20943, showing 5 records out of 104715 total, starting on record 4071, ending on 4075

Actions