CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36598 | CVE-2008-6481 | Candidate | SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php. | Assigned (20090317) | None (candidate not yet proposed) | View | |
102134 | CVE-2017-5314 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170109) | None (candidate not yet proposed) | View | |
36854 | CVE-2008-6737 | Candidate | Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information. | Assigned (20090421) | None (candidate not yet proposed) | View | |
102390 | CVE-2017-5570 | Candidate | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile(). | Assigned (20170123) | None (candidate not yet proposed) | View | |
37110 | CVE-2008-6993 | Candidate | Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20090817) | None (candidate not yet proposed) | View |
Page 20203 of 20943, showing 5 records out of 104715 total, starting on record 101011, ending on 101015