CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11505  CVE-2005-0299  Candidate  Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.  Assigned (20050210)  None (candidate not yet proposed)    View
77041  CVE-2014-9740  Candidate  Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link.  Assigned (20150706)  None (candidate not yet proposed)    View
11761  CVE-2005-0555  Candidate  Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."  Assigned (20050226)  None (candidate not yet proposed)    View
77297  CVE-2015-0034  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141118)  None (candidate not yet proposed)    View
12017  CVE-2005-0811  Candidate  The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a direct request to certain URLs.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 19758 of 20943, showing 5 records out of 104715 total, starting on record 98786, ending on 98790

Actions