CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10987 | CVE-2004-2561 | Candidate | Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp. | Assigned (20051122) | None (candidate not yet proposed) | View | |
76523 | CVE-2014-9222 | Candidate | AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability. | Assigned (20141202) | None (candidate not yet proposed) | View | |
11243 | CVE-2005-0037 | Candidate | The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop. | Assigned (20050107) | None (candidate not yet proposed) | View | |
76779 | CVE-2014-9478 | Candidate | Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to true, allows remote attackers to inject arbitrary web script or HTML via the wpInput parameter to the Special:ExpandTemplates page. | Assigned (20150103) | None (candidate not yet proposed) | View | |
11499 | CVE-2005-0293 | Candidate | Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 19288 of 20943, showing 5 records out of 104715 total, starting on record 96436, ending on 96440