CVE List

Id CVE No. Status Description Phase Votes Comments Actions
84211  CVE-2015-6934  Candidate  Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.  Assigned (20150914)  None (candidate not yet proposed)    View
18931  CVE-2006-2827  Candidate  ** DISPUTED ** SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue in a comment on the original researcher"s blog, saying "the bug does not impose any security threat and remote attackers can"t add, modify, or delete information in the back-end database by sending specially-crafted SQL statements to the search.php script using various search parameters." As of 20060605, the original blog entry is unavailable, although ISS also reports the same dispute. CVE has not been able to investigate this issue further, although the researcher sometimes makes inaccurate claims.  Assigned (20060605)  None (candidate not yet proposed)    View
84467  CVE-2015-7190  Candidate  The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.  Assigned (20150916)  None (candidate not yet proposed)    View
19187  CVE-2006-3083  Candidate  The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.  Assigned (20060619)  None (candidate not yet proposed)    View
84723  CVE-2015-7446  Candidate  Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.  Assigned (20150929)  None (candidate not yet proposed)    View

Page 19326 of 20943, showing 5 records out of 104715 total, starting on record 96626, ending on 96630

Actions