CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71159  CVE-2014-3863  Candidate  Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a file upload in an active JChat chat window.  Assigned (20140525)  None (candidate not yet proposed)    View
71415  CVE-2014-4119  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140612)  None (candidate not yet proposed)    View
6135  CVE-2002-1753  Candidate  csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.  Assigned (20050621)  None (candidate not yet proposed)    View
71671  CVE-2014-4375  Candidate  Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.  Assigned (20140620)  None (candidate not yet proposed)    View
6391  CVE-2002-2009  Candidate  Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 19095 of 20943, showing 5 records out of 104715 total, starting on record 95471, ending on 95475

Actions