CVE List

Id CVE No. Status Description Phase Votes Comments Actions
84461  CVE-2015-7184  Candidate  The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.  Assigned (20150916)  None (candidate not yet proposed)    View
19181  CVE-2006-3077  Candidate  Cross-site scripting (XSS) vulnerability in guestbook.cfm in aXentGuestbook 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter.  Assigned (20060619)  None (candidate not yet proposed)    View
84717  CVE-2015-7440  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150929)  None (candidate not yet proposed)    View
19437  CVE-2006-3333  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multiple unspecified parameters, including the (1) frommethod, (2) list, and (3) method, which are reflected in an error message. NOTE: some of these vectors might be resultant from SQL injection.  Assigned (20060630)  None (candidate not yet proposed)    View
84973  CVE-2015-7696  Candidate  Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.  Assigned (20151004)  None (candidate not yet proposed)    View

Page 18849 of 20943, showing 5 records out of 104715 total, starting on record 94241, ending on 94245

Actions