CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79609  CVE-2015-2332  Candidate  Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150318)  None (candidate not yet proposed)    View
14329  CVE-2005-3123  Candidate  Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.  Assigned (20051003)  None (candidate not yet proposed)    View
79865  CVE-2015-2588  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote attackers to affect integrity via vectors related to PIA Core Technology.  Assigned (20150320)  None (candidate not yet proposed)    View
14585  CVE-2005-3379  Candidate  Multiple interpretation error in Trend Micro (1) PC-Cillin 2005 12.0.1244 with the 7.510.1002 engine and (2) OfficeScan 7.0 with the 7.510.1002 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."  Assigned (20051029)  None (candidate not yet proposed)    View
80121  CVE-2015-2844  Candidate  The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.  Assigned (20150403)  None (candidate not yet proposed)    View

Page 20406 of 20943, showing 5 records out of 104715 total, starting on record 102026, ending on 102030

Actions