CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13298  CVE-2005-2092  Candidate  BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."  Assigned (20050630)  None (candidate not yet proposed)    View
78834  CVE-2015-1557  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150208)  None (candidate not yet proposed)    View
13554  CVE-2005-2348  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20050722)  None (candidate not yet proposed)    View
79090  CVE-2015-1813  Candidate  Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.  Assigned (20150217)  None (candidate not yet proposed)    View
13810  CVE-2005-2604  Candidate  index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message.  Assigned (20050817)  None (candidate not yet proposed)    View

Page 19844 of 20943, showing 5 records out of 104715 total, starting on record 99216, ending on 99220

Actions