CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80657  CVE-2015-3380  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in the Feature Set module for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable or (2) disable a module via unspecified vectors.  Assigned (20150421)  None (candidate not yet proposed)    View
15377  CVE-2005-4173  Candidate  eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.  Assigned (20051211)  None (candidate not yet proposed)    View
80913  CVE-2015-3636  Candidate  The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.  Assigned (20150502)  None (candidate not yet proposed)    View
15633  CVE-2005-4429  Candidate  SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.  Assigned (20051220)  None (candidate not yet proposed)    View
81169  CVE-2015-3892  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150512)  None (candidate not yet proposed)    View

Page 1366 of 20943, showing 5 records out of 104715 total, starting on record 6826, ending on 6830

Actions