CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79093  CVE-2015-1816  Candidate  Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.  Assigned (20150217)  None (candidate not yet proposed)    View
13813  CVE-2005-2607  Candidate  PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null ("%00") characters.  Assigned (20050817)  None (candidate not yet proposed)    View
79349  CVE-2015-2072  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or (2) xs/ide/editor/templates/trace/hanaTraceDetailService.xsjs, aka SAP Note 2069676.  Assigned (20150224)  None (candidate not yet proposed)    View
14069  CVE-2005-2863  Candidate  Cross-site scripting (XSS) vulnerability in openwebmail-main.pl in OpenWebMail 2.41 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.  Assigned (20050908)  None (candidate not yet proposed)    View
79605  CVE-2015-2328  Candidate  PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.  Assigned (20150318)  None (candidate not yet proposed)    View

Page 20088 of 20943, showing 5 records out of 104715 total, starting on record 100436, ending on 100440

Actions