CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78074  CVE-2015-0811  Candidate  The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.  Assigned (20150107)  None (candidate not yet proposed)    View
12794  CVE-2005-1588  Candidate  ** DISPUTED ** SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection.  Assigned (20050514)  None (candidate not yet proposed)    View
78330  CVE-2015-1053  Candidate  Cross-site scripting (XSS) vulnerability in the administrative backend in Croogo before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to admin/file_manager/file_manager/editfile.  Assigned (20150116)  None (candidate not yet proposed)    View
13050  CVE-2005-1844  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20050603)  None (candidate not yet proposed)    View
78586  CVE-2015-1309  Candidate  XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.  Assigned (20150122)  None (candidate not yet proposed)    View

Page 20460 of 20943, showing 5 records out of 104715 total, starting on record 102296, ending on 102300

Actions