CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76541 | CVE-2014-9240 | Candidate | SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action. | Assigned (20141203) | None (candidate not yet proposed) | View | |
11261 | CVE-2005-0055 | Candidate | Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability." | Assigned (20050111) | None (candidate not yet proposed) | View | |
76797 | CVE-2014-9496 | Candidate | The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read. | Assigned (20150103) | None (candidate not yet proposed) | View | |
11517 | CVE-2005-0311 | Candidate | Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources. | Assigned (20050210) | None (candidate not yet proposed) | View | |
77053 | CVE-2014-9752 | Candidate | Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course, then accessing it via a direct request to the file in content/. | Assigned (20151005) | None (candidate not yet proposed) | View |
Page 20720 of 20943, showing 5 records out of 104715 total, starting on record 103596, ending on 103600