CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76521 | CVE-2014-9220 | Candidate | SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command. | Assigned (20141202) | None (candidate not yet proposed) | View | |
11241 | CVE-2005-0035 | Candidate | The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method. | Assigned (20050107) | None (candidate not yet proposed) | View | |
76777 | CVE-2014-9476 | Candidate | MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/." | Assigned (20150103) | None (candidate not yet proposed) | View | |
11497 | CVE-2005-0291 | Candidate | Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase. | Assigned (20050210) | None (candidate not yet proposed) | View | |
77033 | CVE-2014-9732 | Candidate | The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive. | Assigned (20150611) | None (candidate not yet proposed) | View |
Page 19146 of 20943, showing 5 records out of 104715 total, starting on record 95726, ending on 95730