CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10245 | CVE-2004-1818 | Candidate | Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
75781 | CVE-2014-8480 | Candidate | The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intended decoder-table flags for certain RIP-relative instructions, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a crafted application. | Assigned (20141024) | None (candidate not yet proposed) | View | |
10501 | CVE-2004-2075 | Candidate | Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated. | Assigned (20050519) | None (candidate not yet proposed) | View | |
76037 | CVE-2014-8736 | Candidate | The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node. | Assigned (20141112) | None (candidate not yet proposed) | View | |
10757 | CVE-2004-2331 | Candidate | ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag. | Assigned (20050816) | None (candidate not yet proposed) | View |
Page 419 of 20943, showing 5 records out of 104715 total, starting on record 2091, ending on 2095