CVE List

Id CVE No. Status Description Phase Votes Comments Actions
77819  CVE-2015-0556  Candidate  Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.  Assigned (20150105)  None (candidate not yet proposed)    View
12539  CVE-2005-1333  Candidate  Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.  Assigned (20050427)  None (candidate not yet proposed)    View
78075  CVE-2015-0812  Candidate  Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.  Assigned (20150107)  None (candidate not yet proposed)    View
12795  CVE-2005-1589  Candidate  The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.  Assigned (20050516)  None (candidate not yet proposed)    View
78331  CVE-2015-1054  Candidate  Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the Game Content field in Add Game.  Assigned (20150116)  None (candidate not yet proposed)    View

Page 20563 of 20943, showing 5 records out of 104715 total, starting on record 102811, ending on 102815

Actions