CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79627  CVE-2015-2350  Candidate  Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.  Assigned (20150319)  None (candidate not yet proposed)    View
14347  CVE-2005-3141  Candidate  Cerulean Studios Trillian 3.0 allows remote attackers to cause a denial of service (crash) via a reverse direct connection from a different client, as demonstrated using LICQ.  Assigned (20051005)  None (candidate not yet proposed)    View
79883  CVE-2015-2606  Candidate  Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2604, CVE-2015-2605, and CVE-2015-4745.  Assigned (20150320)  None (candidate not yet proposed)    View
14603  CVE-2005-3397  Candidate  Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2.  Assigned (20051101)  None (candidate not yet proposed)    View
80139  CVE-2015-2862  Candidate  Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote authenticated users to read arbitrary files via a crafted HTTP request.  Assigned (20150403)  None (candidate not yet proposed)    View

Page 1509 of 20943, showing 5 records out of 104715 total, starting on record 7541, ending on 7545

Actions