CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12282 | CVE-2005-1076 | Candidate | Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field. | Assigned (20050412) | None (candidate not yet proposed) | View | |
77818 | CVE-2015-0555 | Candidate | Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function. | Assigned (20150105) | None (candidate not yet proposed) | View | |
12538 | CVE-2005-1332 | Candidate | Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory. | Assigned (20050427) | None (candidate not yet proposed) | View | |
78074 | CVE-2015-0811 | Candidate | The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12794 | CVE-2005-1588 | Candidate | ** DISPUTED ** SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection. | Assigned (20050514) | None (candidate not yet proposed) | View |
Page 20480 of 20943, showing 5 records out of 104715 total, starting on record 102396, ending on 102400