CVE List

Id CVE No. Status Description Phase Votes Comments Actions
77035  CVE-2014-9734  Candidate  Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.  Assigned (20150630)  None (candidate not yet proposed)    View
11755  CVE-2005-0549  Candidate  Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.  Assigned (20050225)  None (candidate not yet proposed)    View
77291  CVE-2015-0028  Candidate  Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0048.  Assigned (20141118)  None (candidate not yet proposed)    View
12011  CVE-2005-0805  Candidate  SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.  Assigned (20050320)  None (candidate not yet proposed)    View
77547  CVE-2015-0284  Candidate  Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.  Assigned (20141118)  None (candidate not yet proposed)    View

Page 19289 of 20943, showing 5 records out of 104715 total, starting on record 96441, ending on 96445

Actions