CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81424  CVE-2015-4147  Candidate  The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary code by providing crafted serialized data with an unexpected data type, related to a "type confusion" issue.  Assigned (20150601)  None (candidate not yet proposed)    View
16144  CVE-2006-0040  Candidate  GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.  Assigned (20051220)  None (candidate not yet proposed)    View
81680  CVE-2015-4403  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150606)  None (candidate not yet proposed)    View
16400  CVE-2006-0296  Candidate  The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user"s localstore.rdf file.  Assigned (20060118)  None (candidate not yet proposed)    View
81936  CVE-2015-4659  Candidate  Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.  Assigned (20150618)  None (candidate not yet proposed)    View

Page 1314 of 20943, showing 5 records out of 104715 total, starting on record 6566, ending on 6570

Actions