CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13828 | CVE-2005-2622 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 6.0.2 allows remote attackers to inject arbitrary web script or HTML via the (1) max or (2) ctg parameter. | Assigned (20050819) | None (candidate not yet proposed) | View | |
79364 | CVE-2015-2087 | Candidate | Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors. | Assigned (20150226) | None (candidate not yet proposed) | View | |
14084 | CVE-2005-2878 | Candidate | Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command. | Assigned (20050913) | None (candidate not yet proposed) | View | |
79620 | CVE-2015-2343 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150318) | None (candidate not yet proposed) | View | |
14340 | CVE-2005-3134 | Candidate | Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName). | Assigned (20051004) | None (candidate not yet proposed) | View |
Page 1487 of 20943, showing 5 records out of 104715 total, starting on record 7431, ending on 7435