CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76540 | CVE-2014-9239 | Candidate | SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter. | Assigned (20141203) | None (candidate not yet proposed) | View | |
11260 | CVE-2005-0054 | Candidate | Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability." | Assigned (20050111) | None (candidate not yet proposed) | View | |
76796 | CVE-2014-9495 | Candidate | Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image. | Assigned (20150103) | None (candidate not yet proposed) | View | |
11516 | CVE-2005-0310 | Candidate | Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined. | Assigned (20050210) | None (candidate not yet proposed) | View | |
77052 | CVE-2014-9751 | Candidate | The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine"s network interface with a packet from the ::1 address. | Assigned (20151004) | None (candidate not yet proposed) | View |
Page 20638 of 20943, showing 5 records out of 104715 total, starting on record 103186, ending on 103190