CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
78845 | CVE-2015-1568 | Candidate | Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote attackers to hijack the authentication of users with the "edit gd infinite scroll settings" permission for requests that delete settings via unspecified vectors. | Assigned (20150209) | None (candidate not yet proposed) | View | |
13565 | CVE-2005-2359 | Candidate | The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session. | Assigned (20050726) | None (candidate not yet proposed) | View | |
79101 | CVE-2015-1824 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150217) | None (candidate not yet proposed) | View | |
13821 | CVE-2005-2615 | Candidate | Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id. | Assigned (20050817) | None (candidate not yet proposed) | View | |
79357 | CVE-2015-2080 | Candidate | The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak. | Assigned (20150224) | None (candidate not yet proposed) | View |
Page 20722 of 20943, showing 5 records out of 104715 total, starting on record 103606, ending on 103610