CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
79093 | CVE-2015-1816 | Candidate | Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate. | Assigned (20150217) | None (candidate not yet proposed) | View | |
13813 | CVE-2005-2607 | Candidate | PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null ("%00") characters. | Assigned (20050817) | None (candidate not yet proposed) | View | |
79349 | CVE-2015-2072 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or (2) xs/ide/editor/templates/trace/hanaTraceDetailService.xsjs, aka SAP Note 2069676. | Assigned (20150224) | None (candidate not yet proposed) | View | |
14069 | CVE-2005-2863 | Candidate | Cross-site scripting (XSS) vulnerability in openwebmail-main.pl in OpenWebMail 2.41 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter. | Assigned (20050908) | None (candidate not yet proposed) | View | |
79605 | CVE-2015-2328 | Candidate | PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | Assigned (20150318) | None (candidate not yet proposed) | View |
Page 20088 of 20943, showing 5 records out of 104715 total, starting on record 100436, ending on 100440