CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80125  CVE-2015-2848  Candidate  Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to hijack the authentication of arbitrary users for requests associated with home-automation commands, as demonstrated by a door-unlock command.  Assigned (20150403)  None (candidate not yet proposed)    View
14845  CVE-2005-3641  Candidate  Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.  Assigned (20051116)  None (candidate not yet proposed)    View
80381  CVE-2015-3104  Candidate  Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.  Assigned (20150409)  None (candidate not yet proposed)    View
15101  CVE-2005-3897  Candidate  Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function.  Assigned (20051129)  None (candidate not yet proposed)    View
80637  CVE-2015-3360  Candidate  Cross-site scripting (XSS) vulnerability in the Term Merge module before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150421)  None (candidate not yet proposed)    View

Page 20694 of 20943, showing 5 records out of 104715 total, starting on record 103466, ending on 103470

Actions