CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14861  CVE-2005-3657  Candidate  The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.  Assigned (20051118)  None (candidate not yet proposed)    View
80397  CVE-2015-3120  Candidate  Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-3119, CVE-2015-3121, CVE-2015-3122, and CVE-2015-4433.  Assigned (20150409)  None (candidate not yet proposed)    View
15117  CVE-2005-3913  Candidate  Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the forwardings of other users.  Assigned (20051130)  None (candidate not yet proposed)    View
80653  CVE-2015-3376  Candidate  Cross-site scripting (XSS) vulnerability in the Quizzler module before 7-x.1.16 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.  Assigned (20150421)  None (candidate not yet proposed)    View
15373  CVE-2005-4169  Candidate  Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter to viewstory.php.  Assigned (20051211)  None (candidate not yet proposed)    View

Page 1058 of 20943, showing 5 records out of 104715 total, starting on record 5286, ending on 5290

Actions