CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74251  CVE-2014-6951  Candidate  The OneFile Ignite (aka uk.co.onefile.ignite) application 1.19 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8971  CVE-2004-0543  Candidate  Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.  Assigned (20040608)  None (candidate not yet proposed)    View
74507  CVE-2014-7206  Candidate  The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.  Assigned (20140927)  None (candidate not yet proposed)    View
9227  CVE-2004-0799  Candidate  The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".  Assigned (20040824)  None (candidate not yet proposed)    View
74763  CVE-2014-7462  Candidate  The Fashion Story: Neon 90"s (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View

Page 895 of 20943, showing 5 records out of 104715 total, starting on record 4471, ending on 4475

Actions