CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70418  CVE-2014-3123  Candidate  Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & Title Text" field.  Assigned (20140429)  None (candidate not yet proposed)    View
5138  CVE-2002-0748  Entry  LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline characters, instead of the expected carriage return/newline combinations.        View
70674  CVE-2014-3378  Candidate  tacacsd in Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed TACACS+ packet, aka Bug ID CSCum00468.  Assigned (20140507)  None (candidate not yet proposed)    View
5394  CVE-2002-1006  Entry  Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl.        View
70930  CVE-2014-3634  Candidate  rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.  Assigned (20140514)  None (candidate not yet proposed)    View

Page 1458 of 20943, showing 5 records out of 104715 total, starting on record 7286, ending on 7290

Actions