CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14611 | CVE-2005-3405 | Candidate | ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability. | Assigned (20051101) | None (candidate not yet proposed) | View | |
80147 | CVE-2015-2870 | Candidate | Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element. | Assigned (20150403) | None (candidate not yet proposed) | View | |
14867 | CVE-2005-3663 | Candidate | Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder. | Assigned (20051118) | None (candidate not yet proposed) | View | |
80403 | CVE-2015-3126 | Candidate | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-4429. | Assigned (20150409) | None (candidate not yet proposed) | View | |
15123 | CVE-2005-3919 | Candidate | Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php. | Assigned (20051130) | None (candidate not yet proposed) | View |
Page 1532 of 20943, showing 5 records out of 104715 total, starting on record 7656, ending on 7660