CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12283 | CVE-2005-1077 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php. | Assigned (20050412) | None (candidate not yet proposed) | View | |
77819 | CVE-2015-0556 | Candidate | Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive. | Assigned (20150105) | None (candidate not yet proposed) | View | |
12539 | CVE-2005-1333 | Candidate | Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files. | Assigned (20050427) | None (candidate not yet proposed) | View | |
78075 | CVE-2015-0812 | Candidate | Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12795 | CVE-2005-1589 | Candidate | The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264. | Assigned (20050516) | None (candidate not yet proposed) | View |
Page 20560 of 20943, showing 5 records out of 104715 total, starting on record 102796, ending on 102800