CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11503 | CVE-2005-0297 | Candidate | SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges. | Assigned (20050210) | None (candidate not yet proposed) | View | |
77039 | CVE-2014-9738 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title. | Assigned (20150706) | None (candidate not yet proposed) | View | |
11759 | CVE-2005-0553 | Candidate | Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability". | Assigned (20050226) | None (candidate not yet proposed) | View | |
77295 | CVE-2015-0032 | Candidate | vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability." | Assigned (20141118) | None (candidate not yet proposed) | View | |
12015 | CVE-2005-0809 | Candidate | NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack. | Assigned (20050320) | None (candidate not yet proposed) | View |
Page 19610 of 20943, showing 5 records out of 104715 total, starting on record 98046, ending on 98050