CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
71167 | CVE-2014-3871 | Candidate | Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. NOTE: the b parameter to index.php vector is already covered by CVE-2006-3823. | Assigned (20140527) | None (candidate not yet proposed) | View | |
5887 | CVE-2002-1503 | Candidate | Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdcmd, (3) afd_ctrl, (4) init_afd, (5) mafd, (6) mon_ctrl, (7) show_olog, or (8) udc. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
71423 | CVE-2014-4127 | Candidate | Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | Assigned (20140612) | None (candidate not yet proposed) | View | |
6143 | CVE-2002-1761 | Candidate | Directory traversal vulnerability in PHProjekt 2.0 through 3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences. | Assigned (20050621) | None (candidate not yet proposed) | View | |
71679 | CVE-2014-4383 | Candidate | The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device"s update status via a crafted Last-Modified HTTP response header. | Assigned (20140620) | None (candidate not yet proposed) | View |
Page 20871 of 20943, showing 5 records out of 104715 total, starting on record 104351, ending on 104355