CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76774  CVE-2014-9473  Candidate  Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default upload directory.  Assigned (20150103)  None (candidate not yet proposed)    View
11494  CVE-2005-0288  Candidate  The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users" passwords.  Assigned (20050210)  None (candidate not yet proposed)    View
77030  CVE-2014-9729  Candidate  The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.18.2 does not ensure a certain data-structure size consistency, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.  Assigned (20150603)  None (candidate not yet proposed)    View
11750  CVE-2005-0544  Candidate  phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.  Assigned (20050224)  None (candidate not yet proposed)    View
77286  CVE-2015-0023  Candidate  Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0025.  Assigned (20141118)  None (candidate not yet proposed)    View

Page 18915 of 20943, showing 5 records out of 104715 total, starting on record 94571, ending on 94575

Actions