CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13026  CVE-2005-1820  Candidate  zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.  Assigned (20050601)  None (candidate not yet proposed)    View
78562  CVE-2015-1285  Candidate  The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.  Assigned (20150121)  None (candidate not yet proposed)    View
13282  CVE-2005-2076  Candidate  HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.  Assigned (20050629)  None (candidate not yet proposed)    View
78818  CVE-2015-1541  Candidate  The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.  Assigned (20150206)  None (candidate not yet proposed)    View
13538  CVE-2005-2332  Candidate  Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.  Assigned (20050720)  None (candidate not yet proposed)    View

Page 18609 of 20943, showing 5 records out of 104715 total, starting on record 93041, ending on 93045

Actions