CVE List

Id CVE No. Status Description Phase Votes Comments Actions
101653  CVE-2017-4833  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
36373  CVE-2008-6256  Candidate  SQL injection vulnerability in admincp/admincalendar.php in vBulletin 3.7.3.pl1 allows remote authenticated administrators to execute arbitrary SQL commands via the holidayinfo[recurring] parameter, a different vector than CVE-2005-3022.  Assigned (20090224)  None (candidate not yet proposed)    View
101909  CVE-2017-5089  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170102)  None (candidate not yet proposed)    View
36629  CVE-2008-6512  Candidate  Cross-domain vulnerability in the WorkerPool API in Google Gears before 0.5.4.2 allows remote attackers to bypass the Same Origin Policy and the intended access restrictions of the allowCrossOrigin function by hosting an assumed-safe file type containing Google Gear commands on the target domain, then accessing that file from the attacking domain, whose response headers are not checked and cause the worker code to run in the target domain.  Assigned (20090324)  None (candidate not yet proposed)    View
102165  CVE-2017-5345  Candidate  SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.  Assigned (20170111)  None (candidate not yet proposed)    View

Page 1725 of 20943, showing 5 records out of 104715 total, starting on record 8621, ending on 8625

Actions