CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76817  CVE-2014-9516  Candidate  Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI, related to the "Web Site" input in the Profile section.  Assigned (20150105)  None (candidate not yet proposed)    View
11537  CVE-2005-0331  Candidate  Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.  Assigned (20050210)  None (candidate not yet proposed)    View
77073  CVE-2014-9772  Candidate  The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters.  Assigned (20160420)  None (candidate not yet proposed)    View
11793  CVE-2005-0587  Candidate  Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.  Assigned (20050228)  None (candidate not yet proposed)    View
77329  CVE-2015-0066  Candidate  Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0037, and CVE-2015-0040.  Assigned (20141118)  None (candidate not yet proposed)    View

Page 1360 of 20943, showing 5 records out of 104715 total, starting on record 6796, ending on 6800

Actions