CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76300  CVE-2014-8999  Candidate  SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.  Assigned (20141119)  None (candidate not yet proposed)    View
11020  CVE-2004-2594  Candidate  Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "/" in a pathname argument, as demonstrated by "download /server.cfg".  Assigned (20051129)  None (candidate not yet proposed)    View
76556  CVE-2014-9255  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141204)  None (candidate not yet proposed)    View
11276  CVE-2005-0070  Candidate  Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.  Assigned (20050114)  None (candidate not yet proposed)    View
76812  CVE-2014-9511  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150105)  None (candidate not yet proposed)    View

Page 975 of 20943, showing 5 records out of 104715 total, starting on record 4871, ending on 4875

Actions