CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14838 | CVE-2005-3634 | Candidate | frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter. | Assigned (20051116) | None (candidate not yet proposed) | View | |
80374 | CVE-2015-3097 | Candidate | Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory address for the Flash heap, which makes it easier for attackers to conduct unspecified attacks by predicting this address. | Assigned (20150409) | None (candidate not yet proposed) | View | |
15094 | CVE-2005-3890 | Candidate | Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash and configuration loss) via a page with a large number of gg: URIs. | Assigned (20051129) | None (candidate not yet proposed) | View | |
80630 | CVE-2015-3353 | Candidate | Cross-site scripting (XSS) vulnerability in the Field Display Label module before 7.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the alternate field label in content types settings. | Assigned (20150421) | None (candidate not yet proposed) | View | |
15350 | CVE-2005-4146 | Candidate | Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration information. | Assigned (20051210) | None (candidate not yet proposed) | View |
Page 20169 of 20943, showing 5 records out of 104715 total, starting on record 100841, ending on 100845