CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80628  CVE-2015-3351  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in the Log Watcher module before 6.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable, (2) disable, or (3) delete a report via unspecified vectors.  Assigned (20150421)  None (candidate not yet proposed)    View
15348  CVE-2005-4144  Candidate  Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.  Assigned (20051210)  None (candidate not yet proposed)    View
80884  CVE-2015-3607  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150430)  None (candidate not yet proposed)    View
15604  CVE-2005-4400  Candidate  Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.  Assigned (20051220)  None (candidate not yet proposed)    View
81140  CVE-2015-3863  Candidate  Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation, aka internal bug 22802399.  Assigned (20150512)  None (candidate not yet proposed)    View

Page 20004 of 20943, showing 5 records out of 104715 total, starting on record 100016, ending on 100020

Actions