CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15349  CVE-2005-4145  Candidate  The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack.  Assigned (20051210)  None (candidate not yet proposed)    View
80885  CVE-2015-3608  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150430)  None (candidate not yet proposed)    View
15605  CVE-2005-4401  Candidate  Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter.  Assigned (20051220)  None (candidate not yet proposed)    View
81141  CVE-2015-3864  Candidate  Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.  Assigned (20150512)  None (candidate not yet proposed)    View
15861  CVE-2005-4657  Candidate  Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20060116)  None (candidate not yet proposed)    View

Page 19480 of 20943, showing 5 records out of 104715 total, starting on record 97396, ending on 97400

Actions