CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79594  CVE-2015-2317  Candidate  The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a x08javascript: URL.  Assigned (20150317)  None (candidate not yet proposed)    View
14314  CVE-2005-3108  Candidate  mm/ioremap.c in Linux 2.6 on 64-bit x86 systems allows local users to cause a denial of service or an information leak via an ioremap on a certain memory map that causes the iounmap to perform a lookup of a page that does not exist.  Assigned (20050930)  None (candidate not yet proposed)    View
79850  CVE-2015-2573  Candidate  Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.  Assigned (20150320)  None (candidate not yet proposed)    View
14570  CVE-2005-3364  Candidate  Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.  Assigned (20051029)  None (candidate not yet proposed)    View
80106  CVE-2015-2829  Candidate  Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors.  Assigned (20150401)  None (candidate not yet proposed)    View

Page 18603 of 20943, showing 5 records out of 104715 total, starting on record 93011, ending on 93015

Actions