CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76777  CVE-2014-9476  Candidate  MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/."  Assigned (20150103)  None (candidate not yet proposed)    View
11497  CVE-2005-0291  Candidate  Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.  Assigned (20050210)  None (candidate not yet proposed)    View
77033  CVE-2014-9732  Candidate  The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.  Assigned (20150611)  None (candidate not yet proposed)    View
11753  CVE-2005-0547  Candidate  Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."  Assigned (20050225)  None (candidate not yet proposed)    View
77289  CVE-2015-0026  Candidate  Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.  Assigned (20141118)  None (candidate not yet proposed)    View

Page 19117 of 20943, showing 5 records out of 104715 total, starting on record 95581, ending on 95585

Actions