CVE List

Id CVE No. Status Description Phase Votes Comments Actions
72170  CVE-2014-4873  Candidate  SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.  Assigned (20140710)  None (candidate not yet proposed)    View
6890  CVE-2003-0061  Candidate  Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.  Assigned (20030203)  None (candidate not yet proposed)    View
72426  CVE-2014-5129  Candidate  Cross-site scripting (XSS) vulnerability in Avolve Software ProjectDox 8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140730)  None (candidate not yet proposed)    View
7146  CVE-2003-0318  Candidate  Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.  Assigned (20030519)  None (candidate not yet proposed)    View
72682  CVE-2014-5385  Candidate  com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which makes it easier for remote attackers to guess passwords via a brute force attack.  Assigned (20140821)  None (candidate not yet proposed)    View

Page 19217 of 20943, showing 5 records out of 104715 total, starting on record 96081, ending on 96085

Actions