CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3836  CVE-2001-1032  Entry  admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling admin.php with an upload parameter and specifying the file to copy.        View
69372  CVE-2014-2077  Candidate  Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving "the aria "tags" for screenreaders at the top bar".  Assigned (20140219)  None (candidate not yet proposed)    View
69628  CVE-2014-2333  Candidate  Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.  Assigned (20140312)  None (candidate not yet proposed)    View
4348  CVE-2001-1548  Candidate  ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.  Assigned (20050714)  None (candidate not yet proposed)    View
69884  CVE-2014-2589  Candidate  Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.  Assigned (20140323)  None (candidate not yet proposed)    View

Page 20256 of 20943, showing 5 records out of 104715 total, starting on record 101276, ending on 101280

Actions