CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36876  CVE-2008-6759  Candidate  ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message.  Assigned (20090428)  None (candidate not yet proposed)    View
102412  CVE-2017-5592  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for profanity (0.4.7 - 0.5.0).  Assigned (20170125)  None (candidate not yet proposed)    View
37132  CVE-2008-7015  Candidate  Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.  Assigned (20090818)  None (candidate not yet proposed)    View
102668  CVE-2017-5848  Candidate  The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.  Assigned (20170201)  None (candidate not yet proposed)    View
37388  CVE-2008-7271  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647.  Assigned (20110113)  None (candidate not yet proposed)    View

Page 1623 of 20943, showing 5 records out of 104715 total, starting on record 8111, ending on 8115

Actions