CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9750 | CVE-2004-1322 | Candidate | Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages. | Assigned (20050106) | None (candidate not yet proposed) | View | |
75286 | CVE-2014-7985 | Candidate | Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php. | Assigned (20141008) | None (candidate not yet proposed) | View | |
10006 | CVE-2004-1578 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header. | Assigned (20050220) | None (candidate not yet proposed) | View | |
75542 | CVE-2014-8241 | Candidate | XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052. | Assigned (20141011) | None (candidate not yet proposed) | View | |
10262 | CVE-2004-1835 | Candidate | Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 1742 of 20943, showing 5 records out of 104715 total, starting on record 8706, ending on 8710