CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69135  CVE-2014-1840  Candidate  Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.  Assigned (20140202)  None (candidate not yet proposed)    View
3855  CVE-2001-1051  Candidate  Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
69391  CVE-2014-2096  Candidate  Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0 allows local users to gain privileges via a Trojan horse bin/catfish.py under the current working directory.  Assigned (20140224)  None (candidate not yet proposed)    View
4111  CVE-2001-1307  Candidate  Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
69647  CVE-2014-2352  Candidate  Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname.  Assigned (20140313)  None (candidate not yet proposed)    View

Page 1199 of 20943, showing 5 records out of 104715 total, starting on record 5991, ending on 5995

Actions