CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9483  CVE-2004-1055  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.  Assigned (20041119)  None (candidate not yet proposed)    View
75019  CVE-2014-7718  Candidate  The Travel+Leisure (aka com.magzter.travelleisure) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141003)  None (candidate not yet proposed)    View
9739  CVE-2004-1311  Candidate  Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.  Assigned (20041221)  None (candidate not yet proposed)    View
75275  CVE-2014-7974  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141008)  None (candidate not yet proposed)    View
9995  CVE-2004-1567  Candidate  profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.  Assigned (20050220)  None (candidate not yet proposed)    View

Page 901 of 20943, showing 5 records out of 104715 total, starting on record 4501, ending on 4505

Actions