CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36874  CVE-2008-6757  Candidate  Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.  Assigned (20090428)  None (candidate not yet proposed)    View
102410  CVE-2017-5590  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for ChatSecure (3.2.0 - 4.0.0; only iOS) and Zom (all versions up to 1.0.11; only iOS).  Assigned (20170125)  None (candidate not yet proposed)    View
37130  CVE-2008-7013  Candidate  NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-by-zero error.  Assigned (20090818)  None (candidate not yet proposed)    View
102666  CVE-2017-5846  Candidate  The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.  Assigned (20170201)  None (candidate not yet proposed)    View
37386  CVE-2008-7269  Candidate  Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.  Assigned (20101201)  None (candidate not yet proposed)    View

Page 863 of 20943, showing 5 records out of 104715 total, starting on record 4311, ending on 4315

Actions