CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81156  CVE-2015-3879  Candidate  Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325.  Assigned (20150512)  None (candidate not yet proposed)    View
15876  CVE-2005-4672  Candidate  Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.  Assigned (20060127)  None (candidate not yet proposed)    View
81412  CVE-2015-4135  Candidate  Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter.  Assigned (20150528)  None (candidate not yet proposed)    View
16132  CVE-2006-0028  Candidate  Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.  Assigned (20051130)  None (candidate not yet proposed)    View
81668  CVE-2015-4391  Candidate  Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of users for requests that delete reports via unspecified vectors.  Assigned (20150605)  None (candidate not yet proposed)    View

Page 1490 of 20943, showing 5 records out of 104715 total, starting on record 7446, ending on 7450

Actions