CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71159  CVE-2014-3863  Candidate  Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a file upload in an active JChat chat window.  Assigned (20140525)  None (candidate not yet proposed)    View
5879  CVE-2002-1495  Candidate  Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that are displayed in a pop-up window, and (3) certain malicious attributes within otherwise safe tags, such as onMouseOver.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
71415  CVE-2014-4119  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140612)  None (candidate not yet proposed)    View
6135  CVE-2002-1753  Candidate  csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.  Assigned (20050621)  None (candidate not yet proposed)    View
71671  CVE-2014-4375  Candidate  Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.  Assigned (20140620)  None (candidate not yet proposed)    View

Page 20229 of 20943, showing 5 records out of 104715 total, starting on record 101141, ending on 101145

Actions