CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15348  CVE-2005-4144  Candidate  Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.  Assigned (20051210)  None (candidate not yet proposed)    View
80884  CVE-2015-3607  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150430)  None (candidate not yet proposed)    View
15604  CVE-2005-4400  Candidate  Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.  Assigned (20051220)  None (candidate not yet proposed)    View
81140  CVE-2015-3863  Candidate  Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation, aka internal bug 22802399.  Assigned (20150512)  None (candidate not yet proposed)    View
15860  CVE-2005-4656  Candidate  SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.  Assigned (20060116)  None (candidate not yet proposed)    View

Page 19400 of 20943, showing 5 records out of 104715 total, starting on record 96996, ending on 97000

Actions