CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73987  CVE-2014-6687  Candidate  The wSaudichannelAlNasr (aka com.wSaudichannelAlNasr) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8707  CVE-2004-0279  Candidate  AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
74243  CVE-2014-6943  Candidate  The Konigsleiten (aka com.knigsleiten) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8963  CVE-2004-0535  Candidate  The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.  Assigned (20040604)  None (candidate not yet proposed)    View
74499  CVE-2014-7199  Candidate  Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.  Assigned (20140926)  None (candidate not yet proposed)    View

Page 862 of 20943, showing 5 records out of 104715 total, starting on record 4306, ending on 4310

Actions