CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
79109 | CVE-2015-1832 | Candidate | XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype. | Assigned (20150217) | None (candidate not yet proposed) | View | |
13829 | CVE-2005-2623 | Candidate | ECW-Shop 6.0.2 allows remote attackers to reduce the total cost of their shopping cart by specifying a negative quantity for an item, which causes the price of the item to be subtracted from the total cost. | Assigned (20050819) | None (candidate not yet proposed) | View | |
79365 | CVE-2015-2088 | Candidate | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | Assigned (20150226) | None (candidate not yet proposed) | View | |
14085 | CVE-2005-2879 | Candidate | Advansysperu Software USB Lock Auto-Protect (AP) 1.5 uses a weak encryption scheme to encrypt passwords, which allows local users to gain sensitive information and bypass USB interface protection. | Assigned (20050914) | None (candidate not yet proposed) | View | |
79621 | CVE-2015-2344 | Candidate | Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150318) | None (candidate not yet proposed) | View |
Page 1030 of 20943, showing 5 records out of 104715 total, starting on record 5146, ending on 5150