CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9972 | CVE-2004-1544 | Candidate | Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter. | Assigned (20050218) | None (candidate not yet proposed) | View | |
11662 | CVE-2005-0456 | Candidate | Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code. | Assigned (20050217) | None (candidate not yet proposed) | View | |
11663 | CVE-2005-0457 | Candidate | Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory. | Assigned (20050217) | None (candidate not yet proposed) | View | |
11664 | CVE-2005-0458 | Candidate | Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter. | Assigned (20050217) | None (candidate not yet proposed) | View | |
11665 | CVE-2005-0459 | Candidate | phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message. | Assigned (20050217) | None (candidate not yet proposed) | View |
Page 19769 of 20943, showing 5 records out of 104715 total, starting on record 98841, ending on 98845