CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7947  CVE-2003-1123  Candidate  Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.  Assigned (20050311)  None (candidate not yet proposed)    View
73483  CVE-2014-6184  Candidate  Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through 5.5.4.3, 6.1 through 6.1.5.6, 6.2 before 6.2.5.4, and 6.3 before 6.3.2.3 on UNIX, Linux, and OS X allows local users to gain privileges via unspecified vectors.  Assigned (20140902)  None (candidate not yet proposed)    View
8203  CVE-2003-1379  Candidate  clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals "ifconfig" information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.  Assigned (20071018)  None (candidate not yet proposed)    View
73739  CVE-2014-6439  Candidate  Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140916)  None (candidate not yet proposed)    View
73995  CVE-2014-6695  Candidate  The Wedding Photo Frames-Love Pics (aka com.WeddingPhotoFramesLovePics) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 894 of 20943, showing 5 records out of 104715 total, starting on record 4466, ending on 4470

Actions