CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79099  CVE-2015-1822  Candidate  chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.  Assigned (20150217)  None (candidate not yet proposed)    View
13819  CVE-2005-2613  Candidate  Unknown vulnerability in CPAINT Ajax Toolkit before 1.3-SP allows attackers to execute arbitrary PHP or ASP code or read files via unknown vectors.  Assigned (20050817)  None (candidate not yet proposed)    View
79355  CVE-2015-2078  Candidate  The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, a different vulnerability than CVE-2015-2077.  Assigned (20150224)  None (candidate not yet proposed)    View
14075  CVE-2005-2869  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.  Assigned (20050908)  None (candidate not yet proposed)    View
79611  CVE-2015-2334  Candidate  Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.  Assigned (20150318)  None (candidate not yet proposed)    View

Page 20565 of 20943, showing 5 records out of 104715 total, starting on record 102821, ending on 102825

Actions