CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71940  CVE-2014-4643  Candidate  Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command.  Assigned (20140625)  None (candidate not yet proposed)    View
6660  CVE-2002-2278  Candidate  Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.  Assigned (20071017)  None (candidate not yet proposed)    View
72196  CVE-2014-4899  Candidate  The Indian Cement Review (aka com.magzter.indiancementreview) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
72452  CVE-2014-5155  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140730)  None (candidate not yet proposed)    View
7172  CVE-2003-0344  Candidate  Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.  Assigned (20030528)  None (candidate not yet proposed)    View

Page 939 of 20943, showing 5 records out of 104715 total, starting on record 4691, ending on 4695

Actions