CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9972  CVE-2004-1544  Candidate  Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.  Assigned (20050218)  None (candidate not yet proposed)    View
11662  CVE-2005-0456  Candidate  Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.  Assigned (20050217)  None (candidate not yet proposed)    View
11663  CVE-2005-0457  Candidate  Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.  Assigned (20050217)  None (candidate not yet proposed)    View
11664  CVE-2005-0458  Candidate  Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.  Assigned (20050217)  None (candidate not yet proposed)    View
11665  CVE-2005-0459  Candidate  phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.  Assigned (20050217)  None (candidate not yet proposed)    View

Page 19769 of 20943, showing 5 records out of 104715 total, starting on record 98841, ending on 98845

Actions