CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14838  CVE-2005-3634  Candidate  frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.  Assigned (20051116)  None (candidate not yet proposed)    View
80374  CVE-2015-3097  Candidate  Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address.  Assigned (20150409)  None (candidate not yet proposed)    View
15094  CVE-2005-3890  Candidate  Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash and configuration loss) via a page with a large number of gg: URIs.  Assigned (20051129)  None (candidate not yet proposed)    View
80630  CVE-2015-3353  Candidate  Cross-site scripting (XSS) vulnerability in the Field Display Label module before 7.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the alternate field label in content types settings.  Assigned (20150421)  None (candidate not yet proposed)    View
15350  CVE-2005-4146  Candidate  Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration information.  Assigned (20051210)  None (candidate not yet proposed)    View

Page 20169 of 20943, showing 5 records out of 104715 total, starting on record 100841, ending on 100845

Actions