CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76306 | CVE-2014-9005 | Candidate | Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php. | Assigned (20141119) | None (candidate not yet proposed) | View | |
11026 | CVE-2004-2600 | Candidate | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled. | Assigned (20051129) | None (candidate not yet proposed) | View | |
76562 | CVE-2014-9261 | Candidate | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php. | Assigned (20141204) | None (candidate not yet proposed) | View | |
11282 | CVE-2005-0076 | Candidate | Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library. | Assigned (20050114) | None (candidate not yet proposed) | View | |
76818 | CVE-2014-9517 | Candidate | Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to vb.htm. | Assigned (20150105) | None (candidate not yet proposed) | View |
Page 1447 of 20943, showing 5 records out of 104715 total, starting on record 7231, ending on 7235