CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76779  CVE-2014-9478  Candidate  Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to true, allows remote attackers to inject arbitrary web script or HTML via the wpInput parameter to the Special:ExpandTemplates page.  Assigned (20150103)  None (candidate not yet proposed)    View
11499  CVE-2005-0293  Candidate  Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
77035  CVE-2014-9734  Candidate  Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.  Assigned (20150630)  None (candidate not yet proposed)    View
11755  CVE-2005-0549  Candidate  Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.  Assigned (20050225)  None (candidate not yet proposed)    View
77291  CVE-2015-0028  Candidate  Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0048.  Assigned (20141118)  None (candidate not yet proposed)    View

Page 18678 of 20943, showing 5 records out of 104715 total, starting on record 93386, ending on 93390

Actions