CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12282  CVE-2005-1076  Candidate  Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.  Assigned (20050412)  None (candidate not yet proposed)    View
77818  CVE-2015-0555  Candidate  Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function.  Assigned (20150105)  None (candidate not yet proposed)    View
12538  CVE-2005-1332  Candidate  Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.  Assigned (20050427)  None (candidate not yet proposed)    View
78074  CVE-2015-0811  Candidate  The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.  Assigned (20150107)  None (candidate not yet proposed)    View
12794  CVE-2005-1588  Candidate  ** DISPUTED ** SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection.  Assigned (20050514)  None (candidate not yet proposed)    View

Page 20480 of 20943, showing 5 records out of 104715 total, starting on record 102396, ending on 102400

Actions