CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79091  CVE-2015-1814  Candidate  The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.  Assigned (20150217)  None (candidate not yet proposed)    View
13811  CVE-2005-2605  Candidate  Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.  Assigned (20050817)  None (candidate not yet proposed)    View
79347  CVE-2015-2070  Candidate  SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed.  Assigned (20150224)  None (candidate not yet proposed)    View
14067  CVE-2005-2861  Candidate  Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly injected into an HTML report.  Assigned (20050908)  None (candidate not yet proposed)    View
79603  CVE-2015-2326  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150318)  None (candidate not yet proposed)    View

Page 19318 of 20943, showing 5 records out of 104715 total, starting on record 96586, ending on 96590

Actions