CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
80125 | CVE-2015-2848 | Candidate | Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to hijack the authentication of arbitrary users for requests associated with home-automation commands, as demonstrated by a door-unlock command. | Assigned (20150403) | None (candidate not yet proposed) | View | |
14845 | CVE-2005-3641 | Candidate | Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username. | Assigned (20051116) | None (candidate not yet proposed) | View | |
80381 | CVE-2015-3104 | Candidate | Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors. | Assigned (20150409) | None (candidate not yet proposed) | View | |
15101 | CVE-2005-3897 | Candidate | Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function. | Assigned (20051129) | None (candidate not yet proposed) | View | |
80637 | CVE-2015-3360 | Candidate | Cross-site scripting (XSS) vulnerability in the Term Merge module before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150421) | None (candidate not yet proposed) | View |
Page 20694 of 20943, showing 5 records out of 104715 total, starting on record 103466, ending on 103470