CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14611  CVE-2005-3405  Candidate  ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability.  Assigned (20051101)  None (candidate not yet proposed)    View
80147  CVE-2015-2870  Candidate  Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element.  Assigned (20150403)  None (candidate not yet proposed)    View
14867  CVE-2005-3663  Candidate  Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.  Assigned (20051118)  None (candidate not yet proposed)    View
80403  CVE-2015-3126  Candidate  Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-4429.  Assigned (20150409)  None (candidate not yet proposed)    View
15123  CVE-2005-3919  Candidate  Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php.  Assigned (20051130)  None (candidate not yet proposed)    View

Page 1532 of 20943, showing 5 records out of 104715 total, starting on record 7656, ending on 7660

Actions