CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80135  CVE-2015-2858  Candidate  Datalex airline booking software before 2015-09-03 allows remote attackers to read or write to arbitrary user data via a modified profileId parameter to (1) ValidateFormAction.do or (2) ProfileConfirmEditAddressAction.do.  Assigned (20150403)  None (candidate not yet proposed)    View
14855  CVE-2005-3651  Candidate  Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrary code via crafted packets.  Assigned (20051118)  None (candidate not yet proposed)    View
80391  CVE-2015-3114  Candidate  Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.  Assigned (20150409)  None (candidate not yet proposed)    View
15111  CVE-2005-3907  Candidate  Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrusted Java applets.  Assigned (20051130)  None (candidate not yet proposed)    View
80647  CVE-2015-3370  Candidate  Cross-site request forgery (CSRF) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to hijack the authentication of users with the "node_invite_can_manage_invite" permission for requests that re-enable node invitations via unspecified vectors.  Assigned (20150421)  None (candidate not yet proposed)    View

Page 1192 of 20943, showing 5 records out of 104715 total, starting on record 5956, ending on 5960

Actions