CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72714  CVE-2014-5417  Candidate  Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140822)  None (candidate not yet proposed)    View
7434  CVE-2003-0607  Candidate  Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.  Assigned (20030728)  None (candidate not yet proposed)    View
72970  CVE-2014-5672  Candidate  The NQ Mobile Security & Antivirus (aka com.nqmobile.antivirus20) application 7.2.16.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View
7690  CVE-2003-0866  Candidate  The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.  Assigned (20031015)  None (candidate not yet proposed)    View
73226  CVE-2014-5927  Candidate  The FastCustomer -- Fast Customer (aka www.fastcustomer.com) application 3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140830)  None (candidate not yet proposed)    View

Page 816 of 20943, showing 5 records out of 104715 total, starting on record 4076, ending on 4080

Actions