CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78067  CVE-2015-0804  Candidate  The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.  Assigned (20150107)  None (candidate not yet proposed)    View
12787  CVE-2005-1581  Candidate  Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.  Assigned (20050514)  None (candidate not yet proposed)    View
78323  CVE-2015-1046  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150112)  None (candidate not yet proposed)    View
13043  CVE-2005-1837  Candidate  Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.  Assigned (20050602)  None (candidate not yet proposed)    View
78579  CVE-2015-1302  Candidate  The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.js and out_of_process_instance.cc.  Assigned (20150121)  None (candidate not yet proposed)    View

Page 19920 of 20943, showing 5 records out of 104715 total, starting on record 99596, ending on 99600

Actions