CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81154  CVE-2015-3877  Candidate  Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696.  Assigned (20150512)  None (candidate not yet proposed)    View
15874  CVE-2005-4670  Candidate  Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.  Assigned (20060127)  None (candidate not yet proposed)    View
81410  CVE-2015-4133  Candidate  Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.  Assigned (20150528)  None (candidate not yet proposed)    View
16130  CVE-2006-0026  Candidate  Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).  Assigned (20051130)  None (candidate not yet proposed)    View
81666  CVE-2015-4389  Candidate  The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission.  Assigned (20150605)  None (candidate not yet proposed)    View

Page 186 of 20943, showing 5 records out of 104715 total, starting on record 926, ending on 930

Actions