CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15343  CVE-2005-4139  Candidate  Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.  Assigned (20051209)  None (candidate not yet proposed)    View
80879  CVE-2015-3602  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150430)  None (candidate not yet proposed)    View
15599  CVE-2005-4395  Candidate  Cross-site scripting (XSS) vulnerability in FarCry 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the criteria parameter.  Assigned (20051220)  None (candidate not yet proposed)    View
81135  CVE-2015-3858  Candidate  The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.  Assigned (20150512)  None (candidate not yet proposed)    View
15855  CVE-2005-4651  Candidate  SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.  Assigned (20060114)  None (candidate not yet proposed)    View

Page 19616 of 20943, showing 5 records out of 104715 total, starting on record 98076, ending on 98080

Actions