CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13828  CVE-2005-2622  Candidate  Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 6.0.2 allows remote attackers to inject arbitrary web script or HTML via the (1) max or (2) ctg parameter.  Assigned (20050819)  None (candidate not yet proposed)    View
79364  CVE-2015-2087  Candidate  Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.  Assigned (20150226)  None (candidate not yet proposed)    View
14084  CVE-2005-2878  Candidate  Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.  Assigned (20050913)  None (candidate not yet proposed)    View
79620  CVE-2015-2343  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150318)  None (candidate not yet proposed)    View
14340  CVE-2005-3134  Candidate  Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).  Assigned (20051004)  None (candidate not yet proposed)    View

Page 1487 of 20943, showing 5 records out of 104715 total, starting on record 7431, ending on 7435

Actions