CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76539  CVE-2014-9238  Candidate  D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character.  Assigned (20141203)  None (candidate not yet proposed)    View
11259  CVE-2005-0053  Candidate  Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."  Assigned (20050111)  None (candidate not yet proposed)    View
76795  CVE-2014-9494  Candidate  RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.  Assigned (20150103)  None (candidate not yet proposed)    View
11515  CVE-2005-0309  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
77051  CVE-2014-9750  Candidate  ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.  Assigned (20151004)  None (candidate not yet proposed)    View

Page 20561 of 20943, showing 5 records out of 104715 total, starting on record 102801, ending on 102805

Actions