CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11004 | CVE-2004-2578 | Candidate | phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords. | Assigned (20051128) | None (candidate not yet proposed) | View | |
76540 | CVE-2014-9239 | Candidate | SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter. | Assigned (20141203) | None (candidate not yet proposed) | View | |
11260 | CVE-2005-0054 | Candidate | Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability." | Assigned (20050111) | None (candidate not yet proposed) | View | |
76796 | CVE-2014-9495 | Candidate | Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image. | Assigned (20150103) | None (candidate not yet proposed) | View | |
11516 | CVE-2005-0310 | Candidate | Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 20030 of 20943, showing 5 records out of 104715 total, starting on record 100146, ending on 100150