CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80906  CVE-2015-3629  Candidate  Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.  Assigned (20150501)  None (candidate not yet proposed)    View
15626  CVE-2005-4422  Candidate  Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.  Assigned (20051220)  None (candidate not yet proposed)    View
81162  CVE-2015-3885  Candidate  Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.  Assigned (20150512)  None (candidate not yet proposed)    View
15882  CVE-2005-4678  Candidate  Apple Safari 2.0.2 (aka 416.12) allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20060131)  None (candidate not yet proposed)    View
81418  CVE-2015-4141  Candidate  The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.  Assigned (20150531)  None (candidate not yet proposed)    View

Page 1432 of 20943, showing 5 records out of 104715 total, starting on record 7156, ending on 7160

Actions