CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10007  CVE-2004-1579  Candidate  index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.  Assigned (20050220)  None (candidate not yet proposed)    View
75543  CVE-2014-8242  Candidate  librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.  Assigned (20141012)  None (candidate not yet proposed)    View
10263  CVE-2004-1836  Candidate  SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.  Assigned (20050504)  None (candidate not yet proposed)    View
75799  CVE-2014-8498  Candidate  SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.  Assigned (20141028)  None (candidate not yet proposed)    View
10519  CVE-2004-2093  Candidate  Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in the future.  Assigned (20050519)  None (candidate not yet proposed)    View

Page 1843 of 20943, showing 5 records out of 104715 total, starting on record 9211, ending on 9215

Actions