CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76004 | CVE-2014-8703 | Candidate | Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML. | Assigned (20141109) | None (candidate not yet proposed) | View | |
10724 | CVE-2004-2298 | Candidate | Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential by using the NMAP Credential Generator. | Assigned (20050805) | None (candidate not yet proposed) | View | |
76260 | CVE-2014-8959 | Candidate | Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authenticated users to include and execute arbitrary local files via a crafted geometry-type parameter. | Assigned (20141118) | None (candidate not yet proposed) | View | |
10980 | CVE-2004-2554 | Candidate | Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges. | Assigned (20051121) | None (candidate not yet proposed) | View | |
76516 | CVE-2014-9215 | Candidate | SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email parameter in the forget page vector is already covered by CVE-2012-4034.2. | Assigned (20141202) | None (candidate not yet proposed) | View |
Page 18730 of 20943, showing 5 records out of 104715 total, starting on record 93646, ending on 93650