CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76521  CVE-2014-9220  Candidate  SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.  Assigned (20141202)  None (candidate not yet proposed)    View
11241  CVE-2005-0035  Candidate  The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.  Assigned (20050107)  None (candidate not yet proposed)    View
76777  CVE-2014-9476  Candidate  MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/."  Assigned (20150103)  None (candidate not yet proposed)    View
11497  CVE-2005-0291  Candidate  Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.  Assigned (20050210)  None (candidate not yet proposed)    View
77033  CVE-2014-9732  Candidate  The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.  Assigned (20150611)  None (candidate not yet proposed)    View

Page 19146 of 20943, showing 5 records out of 104715 total, starting on record 95726, ending on 95730

Actions