CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80918  CVE-2015-3641  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150504)  None (candidate not yet proposed)    View
15638  CVE-2005-4434  Candidate  Cross-site scripting (XSS) vulnerability in AbleDesign ReSearch 2.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20051221)  None (candidate not yet proposed)    View
81174  CVE-2015-3897  Candidate  Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.  Assigned (20150512)  None (candidate not yet proposed)    View
15894  CVE-2005-4690  Candidate  Six Apart Movable Type 3.16 allows local users with blog-creation privileges to create or overwrite arbitrary files of certain types (such as HTML and image files) by selecting an arbitrary directory as a blog"s top-level directory. NOTE: this issue can be used in conjunction with CVE-2005-3102 to create or overwrite arbitrary files of all types.  Assigned (20060131)  None (candidate not yet proposed)    View
81430  CVE-2015-4153  Candidate  Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php.  Assigned (20150601)  None (candidate not yet proposed)    View

Page 1751 of 20943, showing 5 records out of 104715 total, starting on record 8751, ending on 8755

Actions