CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30968  CVE-2008-0851  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php.  Assigned (20080220)  None (candidate not yet proposed)    View
96504  CVE-2016-9684  Candidate  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "viewcert" CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn"t properly escape the information it"s passed in the "CERT" variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.  Assigned (20161130)  None (candidate not yet proposed)    View
31224  CVE-2008-1107  Candidate  Multiple stack-based buffer overflows in the Danske Bank e-Sec Control Module ActiveX control (DanskeSikker.ocx) 3.1.0.48, and possibly earlier versions, allow remote attackers to execute arbitrary code via long arguments to unspecified methods, which are not properly handled by a logging function.  Assigned (20080229)  None (candidate not yet proposed)    View
96760  CVE-2016-9940  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161212)  None (candidate not yet proposed)    View
31480  CVE-2008-1363  Candidate  VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."  Assigned (20080317)  None (candidate not yet proposed)    View

Page 20353 of 20943, showing 5 records out of 104715 total, starting on record 101761, ending on 101765

Actions