CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76260  CVE-2014-8959  Candidate  Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authenticated users to include and execute arbitrary local files via a crafted geometry-type parameter.  Assigned (20141118)  None (candidate not yet proposed)    View
10980  CVE-2004-2554  Candidate  Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.  Assigned (20051121)  None (candidate not yet proposed)    View
76516  CVE-2014-9215  Candidate  SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email parameter in the forget page vector is already covered by CVE-2012-4034.2.  Assigned (20141202)  None (candidate not yet proposed)    View
11236  CVE-2005-0030  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20050105)  None (candidate not yet proposed)    View
76772  CVE-2014-9471  Candidate  The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.  Assigned (20150103)  None (candidate not yet proposed)    View

Page 18760 of 20943, showing 5 records out of 104715 total, starting on record 93796, ending on 93800

Actions