CVE List

Id CVE No. Status Description Phase Votes Comments Actions
85495  CVE-2015-8218  Candidate  The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.  Assigned (20151116)  None (candidate not yet proposed)    View
20215  CVE-2006-4111  Candidate  Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.  Assigned (20060814)  None (candidate not yet proposed)    View
85751  CVE-2015-8474  Candidate  Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.  Assigned (20151204)  None (candidate not yet proposed)    View
20471  CVE-2006-4367  Candidate  SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote attackers to execute arbitrary SQL commands via the start parameter.  Assigned (20060825)  None (candidate not yet proposed)    View
86007  CVE-2015-8730  Candidate  epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted packet.  Assigned (20160103)  None (candidate not yet proposed)    View

Page 20240 of 20943, showing 5 records out of 104715 total, starting on record 101196, ending on 101200

Actions