CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12016  CVE-2005-0810  Candidate  SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL.  Assigned (20050320)  None (candidate not yet proposed)    View
77552  CVE-2015-0289  Candidate  The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an application that processes arbitrary PKCS#7 data and providing malformed data with ASN.1 encoding, related to crypto/pkcs7/pk7_doit.c and crypto/pkcs7/pk7_lib.c.  Assigned (20141118)  None (candidate not yet proposed)    View
12272  CVE-2005-1066  Candidate  Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.  Assigned (20050412)  None (candidate not yet proposed)    View
77808  CVE-2015-0545  Candidate  EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.  Assigned (20141217)  None (candidate not yet proposed)    View
12528  CVE-2005-1322  Candidate  Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title.  Assigned (20050427)  None (candidate not yet proposed)    View

Page 19679 of 20943, showing 5 records out of 104715 total, starting on record 98391, ending on 98395

Actions