CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
80657 | CVE-2015-3380 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in the Feature Set module for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable or (2) disable a module via unspecified vectors. | Assigned (20150421) | None (candidate not yet proposed) | View | |
15377 | CVE-2005-4173 | Candidate | eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function. | Assigned (20051211) | None (candidate not yet proposed) | View | |
80913 | CVE-2015-3636 | Candidate | The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect. | Assigned (20150502) | None (candidate not yet proposed) | View | |
15633 | CVE-2005-4429 | Candidate | SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php. | Assigned (20051220) | None (candidate not yet proposed) | View | |
81169 | CVE-2015-3892 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150512) | None (candidate not yet proposed) | View |
Page 1366 of 20943, showing 5 records out of 104715 total, starting on record 6826, ending on 6830