CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79361  CVE-2015-2084  Candidate  Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an edit action in the cnss_social_icon_add page to wp-admin/admin.php.  Assigned (20150225)  None (candidate not yet proposed)    View
14081  CVE-2005-2875  Candidate  Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.  Assigned (20050913)  None (candidate not yet proposed)    View
79617  CVE-2015-2340  Candidate  TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors.  Assigned (20150318)  None (candidate not yet proposed)    View
14337  CVE-2005-3131  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.  Assigned (20051004)  None (candidate not yet proposed)    View
79873  CVE-2015-2596  Candidate  Unspecified vulnerability in Oracle Java SE 7u80 allows remote attackers to affect integrity via unknown vectors related to Hotspot.  Assigned (20150320)  None (candidate not yet proposed)    View

Page 100 of 20943, showing 5 records out of 104715 total, starting on record 496, ending on 500

Actions