CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11030 | CVE-2004-2604 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter. | Assigned (20051129) | None (candidate not yet proposed) | View | |
76566 | CVE-2014-9265 | Candidate | Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors. | Assigned (20141204) | None (candidate not yet proposed) | View | |
11286 | CVE-2005-0080 | Candidate | The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address. | Assigned (20050114) | None (candidate not yet proposed) | View | |
76822 | CVE-2014-9521 | Candidate | Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct request to the file in the uploads directory, as demonstrated by the .php.swp filename. | Assigned (20150105) | None (candidate not yet proposed) | View | |
11542 | CVE-2005-0336 | Candidate | Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing .. sequences and HTML, which results in a directory browsing page that does not properly filter the HTML. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 1744 of 20943, showing 5 records out of 104715 total, starting on record 8716, ending on 8720