CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78583  CVE-2015-1306  Candidate  The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.  Assigned (20150122)  None (candidate not yet proposed)    View
13303  CVE-2005-2097  Candidate  xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.  Assigned (20050630)  None (candidate not yet proposed)    View
78839  CVE-2015-1562  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to admin/user_management.php, (2) data_search parameter to /admin/profile_data.php, or (3) filter parameter to error_log.php.  Assigned (20150208)  None (candidate not yet proposed)    View
13559  CVE-2005-2353  Candidate  run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.  Assigned (20050722)  None (candidate not yet proposed)    View
79095  CVE-2015-1818  Candidate  XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.  Assigned (20150217)  None (candidate not yet proposed)    View

Page 20246 of 20943, showing 5 records out of 104715 total, starting on record 101226, ending on 101230

Actions