CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104208  CVE-2017-7388  Candidate  A Cross-Site Scripting (XSS) was discovered in "wallacepos v1.4.1". The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the "wallacepos-master/myaccount/resetpassword.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View
38928  CVE-2009-1493  Candidate  The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.  Assigned (20090430)  None (candidate not yet proposed)    View
104464  CVE-2017-7644  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170410)  None (candidate not yet proposed)    View
39184  CVE-2009-1749  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.  Assigned (20090521)  None (candidate not yet proposed)    View
39440  CVE-2009-2005  Candidate  Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication of unspecified victims and add new personal agenda items via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 1332 of 20943, showing 5 records out of 104715 total, starting on record 6656, ending on 6660

Actions