CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13303  CVE-2005-2097  Candidate  xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.  Assigned (20050630)  None (candidate not yet proposed)    View
78839  CVE-2015-1562  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to admin/user_management.php, (2) data_search parameter to /admin/profile_data.php, or (3) filter parameter to error_log.php.  Assigned (20150208)  None (candidate not yet proposed)    View
13559  CVE-2005-2353  Candidate  run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.  Assigned (20050722)  None (candidate not yet proposed)    View
79095  CVE-2015-1818  Candidate  XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.  Assigned (20150217)  None (candidate not yet proposed)    View
13815  CVE-2005-2609  Candidate  index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.  Assigned (20050817)  None (candidate not yet proposed)    View

Page 19106 of 20943, showing 5 records out of 104715 total, starting on record 95526, ending on 95530

Actions