CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73484  CVE-2014-6185  Candidate  dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file.  Assigned (20140902)  None (candidate not yet proposed)    View
8204  CVE-2003-1380  Candidate  Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an "ls @../" command, or (2) list files above the root via a "mget @../FILE" command.  Assigned (20071018)  None (candidate not yet proposed)    View
73740  CVE-2014-6440  Candidate  VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.  Assigned (20140916)  None (candidate not yet proposed)    View
73996  CVE-2014-6696  Candidate  The Candy Girl Party Makeover (aka com.bearhugmedia.android_candygirlparty) application 1.0.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
74252  CVE-2014-6952  Candidate  The Manga Facts (aka app.mangafacts.ar) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 971 of 20943, showing 5 records out of 104715 total, starting on record 4851, ending on 4855

Actions