CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80639  CVE-2015-3362  Candidate  Cross-site scripting (XSS) vulnerability in the Video module before 7.x-2.11 for Drupal, when using the video WYSIWYG plugin, allows remote authenticated users to inject arbitrary web script or HTML via a node title.  Assigned (20150421)  None (candidate not yet proposed)    View
15359  CVE-2005-4155  Candidate  registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check. NOTE: it is possible that this is actually a bug in PHP code, in which case this should not be treated as a vulnerability in ATutor.  Assigned (20051211)  None (candidate not yet proposed)    View
80895  CVE-2015-3618  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150430)  None (candidate not yet proposed)    View
15615  CVE-2005-4411  Candidate  Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105.  Assigned (20051220)  None (candidate not yet proposed)    View
81151  CVE-2015-3874  Candidate  The Sonivox components in Android before 5.1.1 LMY48T allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23335715, 23307276, and 23286323.  Assigned (20150512)  None (candidate not yet proposed)    View

Page 20275 of 20943, showing 5 records out of 104715 total, starting on record 101371, ending on 101375

Actions