CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11028 | CVE-2004-2602 | Candidate | PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php. | Assigned (20051129) | None (candidate not yet proposed) | View | |
76564 | CVE-2014-9263 | Candidate | Multiple buffer overflows in the PocketNetNVRMediaClientAxCtrl.NVRMediaViewer.1 control in 3S Pocketnet Tech VMS allow remote attackers to execute arbitrary code via a crafted string to the (1) StartRecord, (2) StartRecordEx, (3) StartScheduledRecord, (4) SetDisplayText, (5) GetONVIFDeviceInformation, (6) GetONVIFProfiles, or (7) GetONVIFStreamUri method or a crafted filename to the (8) SaveCurrentImage or (9) SaveCurrentImageEx method. | Assigned (20141204) | None (candidate not yet proposed) | View | |
11284 | CVE-2005-0078 | Candidate | The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session. | Assigned (20050114) | None (candidate not yet proposed) | View | |
76820 | CVE-2014-9519 | Candidate | SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter. | Assigned (20150105) | None (candidate not yet proposed) | View | |
11540 | CVE-2005-0334 | Candidate | Linksys PSUS4 running firmware 6032 allows remote attackers to cause a denial of service (device crash) via an HTTP POST request containing an unknown parameter without a value. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 1590 of 20943, showing 5 records out of 104715 total, starting on record 7946, ending on 7950