CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9750  CVE-2004-1322  Candidate  Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.  Assigned (20050106)  None (candidate not yet proposed)    View
75286  CVE-2014-7985  Candidate  Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.  Assigned (20141008)  None (candidate not yet proposed)    View
10006  CVE-2004-1578  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.  Assigned (20050220)  None (candidate not yet proposed)    View
75542  CVE-2014-8241  Candidate  XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.  Assigned (20141011)  None (candidate not yet proposed)    View
10262  CVE-2004-1835  Candidate  Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1742 of 20943, showing 5 records out of 104715 total, starting on record 8706, ending on 8710

Actions