CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9489 | CVE-2004-1061 | Candidate | Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter. | Assigned (20041123) | None (candidate not yet proposed) | View | |
75025 | CVE-2014-7724 | Candidate | The Chemssou Blink (aka com.chemssou.blink) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20141003) | None (candidate not yet proposed) | View | |
9745 | CVE-2004-1317 | Candidate | Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command. | Assigned (20041230) | None (candidate not yet proposed) | View | |
75281 | CVE-2014-7980 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings. | Assigned (20141008) | None (candidate not yet proposed) | View | |
10001 | CVE-2004-1573 | Candidate | The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator. | Assigned (20050220) | None (candidate not yet proposed) | View |
Page 1357 of 20943, showing 5 records out of 104715 total, starting on record 6781, ending on 6785