CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13581  CVE-2005-2375  Candidate  Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message.  Assigned (20050726)  None (candidate not yet proposed)    View
79117  CVE-2015-1840  Candidate  jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value.  Assigned (20150217)  None (candidate not yet proposed)    View
13837  CVE-2005-2631  Candidate  Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote attackers to bypass security checks, change the assigned role of a user, or disconnect users.  Assigned (20050820)  None (candidate not yet proposed)    View
79373  CVE-2015-2096  Candidate  Use-after-free vulnerability in the Connect function in the WESPMonitor.WESPMonitorCtrl.1 ActiveX control in WebGate eDVR Manager allows remote attackers to execute arbitrary code via an invalid IP address and a page reload.  Assigned (20150226)  None (candidate not yet proposed)    View
14093  CVE-2005-2887  Candidate  MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2) AutoTheme directory, (3) Blocks directory, (4) admin.php, (5) pnadmin.php, or (6) Topics directory, which reveal the path in an error message.  Assigned (20050914)  None (candidate not yet proposed)    View

Page 1056 of 20943, showing 5 records out of 104715 total, starting on record 5276, ending on 5280

Actions