CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78568  CVE-2015-1291  Candidate  The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web site with crafted JavaScript code and IFRAME elements.  Assigned (20150121)  None (candidate not yet proposed)    View
13288  CVE-2005-2082  Candidate  im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.  Assigned (20050630)  None (candidate not yet proposed)    View
78824  CVE-2015-1547  Candidate  The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.  Assigned (20150207)  None (candidate not yet proposed)    View
13544  CVE-2005-2338  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module.  Assigned (20050721)  None (candidate not yet proposed)    View
79080  CVE-2015-1803  Candidate  The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.  Assigned (20150217)  None (candidate not yet proposed)    View

Page 19072 of 20943, showing 5 records out of 104715 total, starting on record 95356, ending on 95360

Actions