CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11014  CVE-2004-2588  Candidate  Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.  Assigned (20051128)  None (candidate not yet proposed)    View
76550  CVE-2014-9249  Candidate  The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open ports, aka ZEN-15408.  Assigned (20141203)  None (candidate not yet proposed)    View
11270  CVE-2005-0064  Candidate  Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.  Assigned (20050113)  None (candidate not yet proposed)    View
76806  CVE-2014-9505  Candidate  Cross-site scripting (XSS) vulnerability in the School Administration module 7.x-1.x before 7.x-1.8 for Drupal allows remote authenticated users with permission to create or edit a class node to inject arbitrary web script or HTML via a node title.  Assigned (20150103)  None (candidate not yet proposed)    View
11526  CVE-2005-0320  Candidate  Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 496 of 20943, showing 5 records out of 104715 total, starting on record 2476, ending on 2480

Actions