CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
74251 | CVE-2014-6951 | Candidate | The OneFile Ignite (aka uk.co.onefile.ignite) application 1.19 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View | |
8971 | CVE-2004-0543 | Candidate | Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries. | Assigned (20040608) | None (candidate not yet proposed) | View | |
74507 | CVE-2014-7206 | Candidate | The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file. | Assigned (20140927) | None (candidate not yet proposed) | View | |
9227 | CVE-2004-0799 | Candidate | The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm". | Assigned (20040824) | None (candidate not yet proposed) | View | |
74763 | CVE-2014-7462 | Candidate | The Fashion Story: Neon 90"s (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20141003) | None (candidate not yet proposed) | View |
Page 895 of 20943, showing 5 records out of 104715 total, starting on record 4471, ending on 4475