CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
78062 | CVE-2015-0799 | Candidate | The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12782 | CVE-2005-1576 | Candidate | The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files. | Assigned (20050514) | None (candidate not yet proposed) | View | |
78318 | CVE-2015-1041 | Candidate | Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING. | Assigned (20150111) | None (candidate not yet proposed) | View | |
13038 | CVE-2005-1832 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 and earlier allow remote attackers to execute arbitrary web script or HTML via the (1) forums, (2) version, or (3) limit parameter to misc.php, (4) page or (5) datecut parameter to forumdisplay.php, (6) username, (7) email, or (8) email2 parameter to member.php, (9) page or (10) usersearch parameter to memberlist.php, (11) pid or (12) tid parameter to showthread.php, or (13) tid parameter to printthread.php. | Assigned (20050602) | None (candidate not yet proposed) | View | |
78574 | CVE-2015-1297 | Candidate | The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request"s source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension. | Assigned (20150121) | None (candidate not yet proposed) | View |
Page 19529 of 20943, showing 5 records out of 104715 total, starting on record 97641, ending on 97645