CVE List

Id CVE No. Status Description Phase Votes Comments Actions
35045  CVE-2008-4928  Candidate  Cross-site scripting (XSS) vulnerability in the redirect function in functions.php in MyBB (aka MyBulletinBoard) 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter in a removesubscriptions action to moderation.php, related to use of the ajax option to request a JavaScript redirect. NOTE: this can be leveraged to execute PHP code and bypass cross-site request forgery (CSRF) protection.  Assigned (20081104)  None (candidate not yet proposed)    View
100581  CVE-2017-3761  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161216)  None (candidate not yet proposed)    View
35301  CVE-2008-5184  Candidate  The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.  Assigned (20081120)  None (candidate not yet proposed)    View
100837  CVE-2017-4017  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
35557  CVE-2008-5440  Candidate  Unspecified vulnerability in the TimesTen Data Server component in Oracle Database 7.0.5.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this is a format string vulnerability via the msg parameter in the evtdump CGI module.  Assigned (20081211)  None (candidate not yet proposed)    View

Page 18875 of 20943, showing 5 records out of 104715 total, starting on record 94371, ending on 94375

Actions