CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11503  CVE-2005-0297  Candidate  SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.  Assigned (20050210)  None (candidate not yet proposed)    View
77039  CVE-2014-9738  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.  Assigned (20150706)  None (candidate not yet proposed)    View
11759  CVE-2005-0553  Candidate  Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".  Assigned (20050226)  None (candidate not yet proposed)    View
77295  CVE-2015-0032  Candidate  vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."  Assigned (20141118)  None (candidate not yet proposed)    View
12015  CVE-2005-0809  Candidate  NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 19610 of 20943, showing 5 records out of 104715 total, starting on record 98046, ending on 98050

Actions