CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76535  CVE-2014-9234  Candidate  Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  Assigned (20141203)  None (candidate not yet proposed)    View
11255  CVE-2005-0049  Candidate  Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.  Assigned (20050111)  None (candidate not yet proposed)    View
76791  CVE-2014-9490  Candidate  The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.  Assigned (20150103)  None (candidate not yet proposed)    View
11511  CVE-2005-0305  Candidate  CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.  Assigned (20050210)  None (candidate not yet proposed)    View
77047  CVE-2014-9746  Candidate  The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted font.  Assigned (20150925)  None (candidate not yet proposed)    View

Page 20226 of 20943, showing 5 records out of 104715 total, starting on record 101126, ending on 101130

Actions