CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12525  CVE-2005-1319  Candidate  Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title.  Assigned (20050427)  None (candidate not yet proposed)    View
78061  CVE-2015-0798  Candidate  The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.  Assigned (20150107)  None (candidate not yet proposed)    View
12781  CVE-2005-1575  Candidate  The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.  Assigned (20050514)  None (candidate not yet proposed)    View
78317  CVE-2015-1040  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lrealname field in the editProfile form to index.php/home/profile; the (2) data[title] or (3) data[description] field in the addQuickItem form to index.php; the (4) "note text" field in the saveNote form to index.php/areas; or the (5) titleBEObject or (6) tagsArea field in the updateForm form to index.php/documents/view.  Assigned (20150111)  None (candidate not yet proposed)    View
13037  CVE-2005-1831  Candidate  ** DISPUTED ** Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don"t see how this could happen unless the user"s actual password was empty."  Assigned (20050602)  None (candidate not yet proposed)    View

Page 19439 of 20943, showing 5 records out of 104715 total, starting on record 97191, ending on 97195

Actions