CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14833  CVE-2005-3629  Candidate  initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.  Assigned (20051116)  None (candidate not yet proposed)    View
80369  CVE-2015-3092  Candidate  Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3091.  Assigned (20150409)  None (candidate not yet proposed)    View
15089  CVE-2005-3885  Candidate  The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.  Assigned (20051129)  None (candidate not yet proposed)    View
80625  CVE-2015-3348  Candidate  Cross-site scripting (XSS) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.  Assigned (20150421)  None (candidate not yet proposed)    View
15345  CVE-2005-4141  Candidate  Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.  Assigned (20051209)  None (candidate not yet proposed)    View

Page 19161 of 20943, showing 5 records out of 104715 total, starting on record 95801, ending on 95805

Actions