CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78053  CVE-2015-0790  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150107)  None (candidate not yet proposed)    View
12773  CVE-2005-1567  Candidate  SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.  Assigned (20050514)  None (candidate not yet proposed)    View
78309  CVE-2015-1032  Candidate  Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to /search.  Assigned (20150110)  None (candidate not yet proposed)    View
13029  CVE-2005-1823  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.  Assigned (20050601)  None (candidate not yet proposed)    View
78565  CVE-2015-1288  Candidate  The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263.  Assigned (20150121)  None (candidate not yet proposed)    View

Page 18840 of 20943, showing 5 records out of 104715 total, starting on record 94196, ending on 94200

Actions