CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76044  CVE-2014-8743  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role or (2) Organic Group name.  Assigned (20141013)  None (candidate not yet proposed)    View
10764  CVE-2004-2338  Candidate  OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.  Assigned (20050816)  None (candidate not yet proposed)    View
76300  CVE-2014-8999  Candidate  SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.  Assigned (20141119)  None (candidate not yet proposed)    View
11020  CVE-2004-2594  Candidate  Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "/" in a pathname argument, as demonstrated by "download /server.cfg".  Assigned (20051129)  None (candidate not yet proposed)    View
76556  CVE-2014-9255  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141204)  None (candidate not yet proposed)    View

Page 1582 of 20943, showing 5 records out of 104715 total, starting on record 7906, ending on 7910

Actions