CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81135  CVE-2015-3858  Candidate  The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.  Assigned (20150512)  None (candidate not yet proposed)    View
15855  CVE-2005-4651  Candidate  SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.  Assigned (20060114)  None (candidate not yet proposed)    View
81391  CVE-2015-4114  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150528)  None (candidate not yet proposed)    View
16111  CVE-2006-0007  Candidate  Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.  Assigned (20051109)  None (candidate not yet proposed)    View
81647  CVE-2015-4370  Candidate  Cross-site scripting (XSS) vulnerability in the Site Documentation module before 6.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms.  Assigned (20150605)  None (candidate not yet proposed)    View

Page 19003 of 20943, showing 5 records out of 104715 total, starting on record 95011, ending on 95015

Actions