CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12807 | CVE-2005-1601 | Candidate | MRO Maximo Self Service 4 and 5 stores certain information under the web document root using file extensions that are not processed by Tomcat, which allows remote attackers to obtain sensitive information via a direct request for the file, such as MXServer.properties. | Assigned (20050516) | None (candidate not yet proposed) | View | |
78343 | CVE-2015-1066 | Candidate | Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app. | Assigned (20150116) | None (candidate not yet proposed) | View | |
13063 | CVE-2005-1857 | Candidate | Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply. | Assigned (20050606) | None (candidate not yet proposed) | View | |
78599 | CVE-2015-1322 | Candidate | Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0ubuntu7.1 allows local users to change the modem device configuration or read arbitrary files via a .. (dot dot) in the file name in a request to read modem device contexts (com.canonical.NMOfono.ReadImsiContexts). | Assigned (20150122) | None (candidate not yet proposed) | View | |
13319 | CVE-2005-2113 | Candidate | SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method. | Assigned (20050701) | None (candidate not yet proposed) | View |
Page 1189 of 20943, showing 5 records out of 104715 total, starting on record 5941, ending on 5945