CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
77811 | CVE-2015-0548 | Candidate | The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors. | Assigned (20141217) | None (candidate not yet proposed) | View | |
12531 | CVE-2005-1325 | Candidate | set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter. | Assigned (20050427) | None (candidate not yet proposed) | View | |
78067 | CVE-2015-0804 | Candidate | The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12787 | CVE-2005-1581 | Candidate | Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php. | Assigned (20050514) | None (candidate not yet proposed) | View | |
78323 | CVE-2015-1046 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150112) | None (candidate not yet proposed) | View |
Page 19316 of 20943, showing 5 records out of 104715 total, starting on record 96576, ending on 96580