CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11014 | CVE-2004-2588 | Candidate | Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application. | Assigned (20051128) | None (candidate not yet proposed) | View | |
76550 | CVE-2014-9249 | Candidate | The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open ports, aka ZEN-15408. | Assigned (20141203) | None (candidate not yet proposed) | View | |
11270 | CVE-2005-0064 | Candidate | Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value. | Assigned (20050113) | None (candidate not yet proposed) | View | |
76806 | CVE-2014-9505 | Candidate | Cross-site scripting (XSS) vulnerability in the School Administration module 7.x-1.x before 7.x-1.8 for Drupal allows remote authenticated users with permission to create or edit a class node to inject arbitrary web script or HTML via a node title. | Assigned (20150103) | None (candidate not yet proposed) | View | |
11526 | CVE-2005-0320 | Candidate | Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 496 of 20943, showing 5 records out of 104715 total, starting on record 2476, ending on 2480