CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15116  CVE-2005-3912  Candidate  Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is ultimately used in a syslog call. NOTE: the code execution might be associated with an issue in Perl.  Assigned (20051130)  None (candidate not yet proposed)    View
80652  CVE-2015-3375  Candidate  Cross-site request forgery (CSRF) vulnerability in the Shibboleth Authentication module before 6.x-4.1 and 7.x-4.x before 7.x-4.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete user role matching rules via unspecified vectors.  Assigned (20150421)  None (candidate not yet proposed)    View
15372  CVE-2005-4168  Candidate  Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username.  Assigned (20051211)  None (candidate not yet proposed)    View
80908  CVE-2015-3631  Candidate  Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.  Assigned (20150501)  None (candidate not yet proposed)    View
15628  CVE-2005-4424  Candidate  Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.  Assigned (20051220)  None (candidate not yet proposed)    View

Page 1589 of 20943, showing 5 records out of 104715 total, starting on record 7941, ending on 7945

Actions