CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
79361 | CVE-2015-2084 | Candidate | Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an edit action in the cnss_social_icon_add page to wp-admin/admin.php. | Assigned (20150225) | None (candidate not yet proposed) | View | |
14081 | CVE-2005-2875 | Candidate | Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes. | Assigned (20050913) | None (candidate not yet proposed) | View | |
79617 | CVE-2015-2340 | Candidate | TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors. | Assigned (20150318) | None (candidate not yet proposed) | View | |
14337 | CVE-2005-3131 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html. | Assigned (20051004) | None (candidate not yet proposed) | View | |
79873 | CVE-2015-2596 | Candidate | Unspecified vulnerability in Oracle Java SE 7u80 allows remote attackers to affect integrity via unknown vectors related to Hotspot. | Assigned (20150320) | None (candidate not yet proposed) | View |
Page 100 of 20943, showing 5 records out of 104715 total, starting on record 496, ending on 500