CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76800  CVE-2014-9499  Candidate  Cross-site scripting (XSS) vulnerability in the Godwin"s Law module before 7.x-1.1 for Drupal, when using the dblog module, allows remote authenticated users to inject arbitrary web script or HTML via a Watchdog message.  Assigned (20150103)  None (candidate not yet proposed)    View
11520  CVE-2005-0314  Candidate  Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.  Assigned (20050210)  None (candidate not yet proposed)    View
77056  CVE-2014-9755  Candidate  The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint"s SSL key) before initiating the exchange, which allows remote attackers to perform a replay attack.  Assigned (20151102)  None (candidate not yet proposed)    View
11776  CVE-2005-0570  Candidate  profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user"s password to NULL.  Assigned (20050227)  None (candidate not yet proposed)    View
77312  CVE-2015-0049  Candidate  Microsoft Internet Explorer 8 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."  Assigned (20141118)  None (candidate not yet proposed)    View

Page 627 of 20943, showing 5 records out of 104715 total, starting on record 3131, ending on 3135

Actions