CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
78070 | CVE-2015-0807 | Candidate | The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12790 | CVE-2005-1584 | Candidate | Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action. | Assigned (20050514) | None (candidate not yet proposed) | View | |
78326 | CVE-2015-1049 | Candidate | The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors. | Assigned (20150113) | None (candidate not yet proposed) | View | |
13046 | CVE-2005-1840 | Candidate | Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php. | Assigned (20050602) | None (candidate not yet proposed) | View | |
78582 | CVE-2015-1305 | Candidate | McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call. | Assigned (20150122) | None (candidate not yet proposed) | View |
Page 20160 of 20943, showing 5 records out of 104715 total, starting on record 100796, ending on 100800