CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80642  CVE-2015-3365  Candidate  Cross-site scripting (XSS) vulnerability in the nodeauthor module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a Profile2 field in a provided block.  Assigned (20150421)  None (candidate not yet proposed)    View
15362  CVE-2005-4158  Candidate  Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.  Assigned (20051211)  None (candidate not yet proposed)    View
80898  CVE-2015-3621  Candidate  Untrusted search path vulnerability in SAP Enterprise Central Component (ECC) allows local users to gain privileges via a Trojan horse program.  Assigned (20150430)  None (candidate not yet proposed)    View
15618  CVE-2005-4414  Candidate  Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug."  Assigned (20051220)  None (candidate not yet proposed)    View
81154  CVE-2015-3877  Candidate  Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696.  Assigned (20150512)  None (candidate not yet proposed)    View

Page 182 of 20943, showing 5 records out of 104715 total, starting on record 906, ending on 910

Actions