CVE List

Id CVE No. Status Description Phase Votes Comments Actions
77540  CVE-2015-0277  Candidate  The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to other users" accounts via a crafted SAML assertion. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6254 for lack of validation for the Destination attribute in a Response element in a SAML assertion.  Assigned (20141118)  None (candidate not yet proposed)    View
12260  CVE-2005-1054  Candidate  PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.  Assigned (20050412)  None (candidate not yet proposed)    View
77796  CVE-2015-0533  Candidate  EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE SSL-C 2.8.9 and earlier allow remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message, a similar issue to CVE-2014-3572.  Assigned (20141217)  None (candidate not yet proposed)    View
12516  CVE-2005-1310  Candidate  SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.  Assigned (20050427)  None (candidate not yet proposed)    View
78052  CVE-2015-0789  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150107)  None (candidate not yet proposed)    View

Page 18762 of 20943, showing 5 records out of 104715 total, starting on record 93806, ending on 93810

Actions