CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37859  CVE-2009-0424  Candidate  Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from third party information.  Assigned (20090204)  None (candidate not yet proposed)    View
103395  CVE-2017-6575  Candidate  A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member_id.  Assigned (20170309)  None (candidate not yet proposed)    View
38115  CVE-2009-0680  Candidate  cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences.  Assigned (20090222)  None (candidate not yet proposed)    View
103651  CVE-2017-6831  Candidate  Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.  Assigned (20170312)  None (candidate not yet proposed)    View
38371  CVE-2009-0936  Candidate  Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."  Assigned (20090317)  None (candidate not yet proposed)    View

Page 18725 of 20943, showing 5 records out of 104715 total, starting on record 93621, ending on 93625

Actions