CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15348 | CVE-2005-4144 | Candidate | Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace. | Assigned (20051210) | None (candidate not yet proposed) | View | |
80884 | CVE-2015-3607 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150430) | None (candidate not yet proposed) | View | |
15604 | CVE-2005-4400 | Candidate | Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters. | Assigned (20051220) | None (candidate not yet proposed) | View | |
81140 | CVE-2015-3863 | Candidate | Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation, aka internal bug 22802399. | Assigned (20150512) | None (candidate not yet proposed) | View | |
15860 | CVE-2005-4656 | Candidate | SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter. | Assigned (20060116) | None (candidate not yet proposed) | View |
Page 19400 of 20943, showing 5 records out of 104715 total, starting on record 96996, ending on 97000