CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15349 | CVE-2005-4145 | Candidate | The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack. | Assigned (20051210) | None (candidate not yet proposed) | View | |
80885 | CVE-2015-3608 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150430) | None (candidate not yet proposed) | View | |
15605 | CVE-2005-4401 | Candidate | Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter. | Assigned (20051220) | None (candidate not yet proposed) | View | |
81141 | CVE-2015-3864 | Candidate | Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824. | Assigned (20150512) | None (candidate not yet proposed) | View | |
15861 | CVE-2005-4657 | Candidate | Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20060116) | None (candidate not yet proposed) | View |
Page 19480 of 20943, showing 5 records out of 104715 total, starting on record 97396, ending on 97400