CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80626  CVE-2015-3349  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in the Htaccess module before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) deploy or (2) delete an .htaccess file via unspecified vectors.  Assigned (20150421)  None (candidate not yet proposed)    View
15346  CVE-2005-4142  Candidate  The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.  Assigned (20051210)  None (candidate not yet proposed)    View
80882  CVE-2015-3605  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150430)  None (candidate not yet proposed)    View
15602  CVE-2005-4398  Candidate  ** DISPUTED ** NOTE: the vendor has disputed this issue. Cross-site scripting (XSS) vulnerability in lemoon 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter. NOTE: the vendor has disputed this issue, saying "Sites are built on top of ASP.NET and you use lemoon core objects to easily manage and render content. The XSS vuln. you are referring to exists in one of our public sites built on lemoon i.e. a custom made site (as all sites are). The problem exists in a UserControl that handles form input and is in no way related to the lemoon core product."  Assigned (20051220)  None (candidate not yet proposed)    View
81138  CVE-2015-3861  Candidate  Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allow remote attackers to cause a denial of service (device inoperability) via crafted Matroska data, aka internal bug 21296336.  Assigned (20150512)  None (candidate not yet proposed)    View

Page 19847 of 20943, showing 5 records out of 104715 total, starting on record 99231, ending on 99235

Actions