CVE List

Id CVE No. Status Description Phase Votes Comments Actions
33778  CVE-2008-3661  Candidate  Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.  Assigned (20080812)  None (candidate not yet proposed)    View
99314  CVE-2017-2494  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View
34034  CVE-2008-3917  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action.  Assigned (20080904)  None (candidate not yet proposed)    View
99570  CVE-2017-2750  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View
34290  CVE-2008-4173  Candidate  SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI.  Assigned (20080922)  None (candidate not yet proposed)    View

Page 19876 of 20943, showing 5 records out of 104715 total, starting on record 99376, ending on 99380

Actions