CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10986  CVE-2004-2560  Candidate  DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi".  Assigned (20051122)  None (candidate not yet proposed)    View
76522  CVE-2014-9221  Candidate  strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.  Assigned (20141202)  None (candidate not yet proposed)    View
11242  CVE-2005-0036  Candidate  The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.  Assigned (20050107)  None (candidate not yet proposed)    View
76778  CVE-2014-9477  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) url parameter.  Assigned (20150103)  None (candidate not yet proposed)    View
11498  CVE-2005-0292  Candidate  Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 18598 of 20943, showing 5 records out of 104715 total, starting on record 92986, ending on 92990

Actions