CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76539 | CVE-2014-9238 | Candidate | D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character. | Assigned (20141203) | None (candidate not yet proposed) | View | |
11259 | CVE-2005-0053 | Candidate | Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability." | Assigned (20050111) | None (candidate not yet proposed) | View | |
76795 | CVE-2014-9494 | Candidate | RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header. | Assigned (20150103) | None (candidate not yet proposed) | View | |
11515 | CVE-2005-0309 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
77051 | CVE-2014-9750 | Candidate | ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field. | Assigned (20151004) | None (candidate not yet proposed) | View |
Page 20561 of 20943, showing 5 records out of 104715 total, starting on record 102801, ending on 102805