CVE List

Id CVE No. Status Description Phase Votes Comments Actions
82453  CVE-2015-5176  Candidate  The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.  Assigned (20150701)  None (candidate not yet proposed)    View
17173  CVE-2006-1069  Candidate  Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.  Assigned (20060307)  None (candidate not yet proposed)    View
82709  CVE-2015-5432  Candidate  HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.  Assigned (20150707)  None (candidate not yet proposed)    View
17429  CVE-2006-1325  Candidate  Cross-site scripting (XSS) vulnerability in Streber 0.055 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  Assigned (20060320)  None (candidate not yet proposed)    View
82965  CVE-2015-5688  Candidate  Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.  Assigned (20150727)  None (candidate not yet proposed)    View

Page 1695 of 20943, showing 5 records out of 104715 total, starting on record 8471, ending on 8475

Actions