CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14092  CVE-2005-2886  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.73, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via (1) the print parameter to the print module, the sitename parameter to (2) bb_smilies or (3) bbcode_ref module, or (4) the hlpfile parameter to openwindow.php.  Assigned (20050914)  None (candidate not yet proposed)    View
79628  CVE-2015-2351  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource parameter to system/workplace/locales/en/help/index.html, (3) path parameter to system/workplace/views/admin/admin-main.jsp, (4) mode parameter to system/workplace/views/explorer/explorer_files.jsp, or (5) query parameter in a search action to system/modules/org.opencms.workplace.help/elements/search.jsp.  Assigned (20150319)  None (candidate not yet proposed)    View
14348  CVE-2005-3142  Candidate  Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header.  Assigned (20051005)  None (candidate not yet proposed)    View
79884  CVE-2015-2607  Candidate  Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.0.2, 3.1.1, 3.1.2, 11.0, and 11.1 allows remote attackers to affect confidentiality via unknown vectors related to Content Acquisition System.  Assigned (20150320)  None (candidate not yet proposed)    View
14604  CVE-2005-3398  Candidate  The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.  Assigned (20051101)  None (candidate not yet proposed)    View

Page 989 of 20943, showing 5 records out of 104715 total, starting on record 4941, ending on 4945

Actions