CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79109  CVE-2015-1832  Candidate  XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.  Assigned (20150217)  None (candidate not yet proposed)    View
13829  CVE-2005-2623  Candidate  ECW-Shop 6.0.2 allows remote attackers to reduce the total cost of their shopping cart by specifying a negative quantity for an item, which causes the price of the item to be subtracted from the total cost.  Assigned (20050819)  None (candidate not yet proposed)    View
79365  CVE-2015-2088  Candidate  Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors.  Assigned (20150226)  None (candidate not yet proposed)    View
14085  CVE-2005-2879  Candidate  Advansysperu Software USB Lock Auto-Protect (AP) 1.5 uses a weak encryption scheme to encrypt passwords, which allows local users to gain sensitive information and bypass USB interface protection.  Assigned (20050914)  None (candidate not yet proposed)    View
79621  CVE-2015-2344  Candidate  Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150318)  None (candidate not yet proposed)    View

Page 1030 of 20943, showing 5 records out of 104715 total, starting on record 5146, ending on 5150

Actions