CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78070  CVE-2015-0807  Candidate  The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.  Assigned (20150107)  None (candidate not yet proposed)    View
12790  CVE-2005-1584  Candidate  Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.  Assigned (20050514)  None (candidate not yet proposed)    View
78326  CVE-2015-1049  Candidate  The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.  Assigned (20150113)  None (candidate not yet proposed)    View
13046  CVE-2005-1840  Candidate  Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.  Assigned (20050602)  None (candidate not yet proposed)    View
78582  CVE-2015-1305  Candidate  McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.  Assigned (20150122)  None (candidate not yet proposed)    View

Page 20160 of 20943, showing 5 records out of 104715 total, starting on record 100796, ending on 100800

Actions