CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12785 | CVE-2005-1579 | Candidate | Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker. | Assigned (20050514) | None (candidate not yet proposed) | View | |
78321 | CVE-2015-1044 | Candidate | vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors. | Assigned (20150112) | None (candidate not yet proposed) | View | |
13041 | CVE-2005-1835 | Candidate | NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb. | Assigned (20050602) | None (candidate not yet proposed) | View | |
78577 | CVE-2015-1300 | Candidate | The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call. | Assigned (20150121) | None (candidate not yet proposed) | View | |
13297 | CVE-2005-2091 | Candidate | IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling." | Assigned (20050630) | None (candidate not yet proposed) | View |
Page 19766 of 20943, showing 5 records out of 104715 total, starting on record 98826, ending on 98830