CVE List

Id CVE No. Status Description Phase Votes Comments Actions
77811  CVE-2015-0548  Candidate  The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.  Assigned (20141217)  None (candidate not yet proposed)    View
12531  CVE-2005-1325  Candidate  set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.  Assigned (20050427)  None (candidate not yet proposed)    View
78067  CVE-2015-0804  Candidate  The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.  Assigned (20150107)  None (candidate not yet proposed)    View
12787  CVE-2005-1581  Candidate  Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.  Assigned (20050514)  None (candidate not yet proposed)    View
78323  CVE-2015-1046  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150112)  None (candidate not yet proposed)    View

Page 19316 of 20943, showing 5 records out of 104715 total, starting on record 96576, ending on 96580

Actions