CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10237  CVE-2004-1810  Candidate  The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array.  Assigned (20050504)  None (candidate not yet proposed)    View
75773  CVE-2014-8472  Candidate  CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.  Assigned (20141024)  None (candidate not yet proposed)    View
10493  CVE-2004-2067  Candidate  SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
76029  CVE-2014-8728  Candidate  SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System and FMS) 7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ranger_user[name] parameter.  Assigned (20141110)  None (candidate not yet proposed)    View
10749  CVE-2004-2323  Candidate  DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.  Assigned (20050816)  None (candidate not yet proposed)    View

Page 20717 of 20943, showing 5 records out of 104715 total, starting on record 103581, ending on 103585

Actions