CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78082  CVE-2015-0819  Candidate  The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.  Assigned (20150107)  None (candidate not yet proposed)    View
12802  CVE-2005-1596  Candidate  index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
78338  CVE-2015-1061  Candidate  IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.  Assigned (20150116)  None (candidate not yet proposed)    View
13058  CVE-2005-1852  Candidate  Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.  Assigned (20050606)  None (candidate not yet proposed)    View
78594  CVE-2015-1317  Candidate  Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.  Assigned (20150122)  None (candidate not yet proposed)    View

Page 178 of 20943, showing 5 records out of 104715 total, starting on record 886, ending on 890

Actions