CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36617  CVE-2008-6500  Candidate  Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.  Assigned (20090320)  None (candidate not yet proposed)    View
102153  CVE-2017-5333  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170110)  None (candidate not yet proposed)    View
36873  CVE-2008-6756  Candidate  ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.  Assigned (20090427)  None (candidate not yet proposed)    View
102409  CVE-2017-5589  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).  Assigned (20170125)  None (candidate not yet proposed)    View
37129  CVE-2008-7012  Candidate  courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.  Assigned (20090818)  None (candidate not yet proposed)    View

Page 782 of 20943, showing 5 records out of 104715 total, starting on record 3906, ending on 3910

Actions