CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76541  CVE-2014-9240  Candidate  SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.  Assigned (20141203)  None (candidate not yet proposed)    View
11261  CVE-2005-0055  Candidate  Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."  Assigned (20050111)  None (candidate not yet proposed)    View
76797  CVE-2014-9496  Candidate  The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.  Assigned (20150103)  None (candidate not yet proposed)    View
11517  CVE-2005-0311  Candidate  Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.  Assigned (20050210)  None (candidate not yet proposed)    View
77053  CVE-2014-9752  Candidate  Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course, then accessing it via a direct request to the file in content/.  Assigned (20151005)  None (candidate not yet proposed)    View

Page 20720 of 20943, showing 5 records out of 104715 total, starting on record 103596, ending on 103600

Actions