CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79344  CVE-2015-2067  Candidate  Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  Assigned (20150224)  None (candidate not yet proposed)    View
14064  CVE-2005-2858  Candidate  The Fetch.FetchContact.1 ActiveX control (Fetch.dll) for Rediff Bol 7.0 allows remote attackers to read the Windows Address Book via the FullAddressBook method.  Assigned (20050908)  None (candidate not yet proposed)    View
79600  CVE-2015-2323  Candidate  FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.  Assigned (20150318)  None (candidate not yet proposed)    View
14320  CVE-2005-3114  Candidate  Buffer overflow in the ActiveX control for NateOn Messenger (NateonDownloadManager.ocx) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long third argument to the GotNate.Excute method.  Assigned (20050930)  None (candidate not yet proposed)    View
79856  CVE-2015-2579  Candidate  Unspecified vulnerability in the Oracle Health Sciences Argus Safety component in Oracle Health Sciences Applications 8.0 allows local users to affect confidentiality via vectors related to BIP Installer.  Assigned (20150320)  None (candidate not yet proposed)    View

Page 19682 of 20943, showing 5 records out of 104715 total, starting on record 98406, ending on 98410

Actions