CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10987  CVE-2004-2561  Candidate  Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.  Assigned (20051122)  None (candidate not yet proposed)    View
76523  CVE-2014-9222  Candidate  AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.  Assigned (20141202)  None (candidate not yet proposed)    View
11243  CVE-2005-0037  Candidate  The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.  Assigned (20050107)  None (candidate not yet proposed)    View
76779  CVE-2014-9478  Candidate  Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to true, allows remote attackers to inject arbitrary web script or HTML via the wpInput parameter to the Special:ExpandTemplates page.  Assigned (20150103)  None (candidate not yet proposed)    View
11499  CVE-2005-0293  Candidate  Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 19288 of 20943, showing 5 records out of 104715 total, starting on record 96436, ending on 96440

Actions