CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78845  CVE-2015-1568  Candidate  Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote attackers to hijack the authentication of users with the "edit gd infinite scroll settings" permission for requests that delete settings via unspecified vectors.  Assigned (20150209)  None (candidate not yet proposed)    View
13565  CVE-2005-2359  Candidate  The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.  Assigned (20050726)  None (candidate not yet proposed)    View
79101  CVE-2015-1824  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150217)  None (candidate not yet proposed)    View
13821  CVE-2005-2615  Candidate  Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.  Assigned (20050817)  None (candidate not yet proposed)    View
79357  CVE-2015-2080  Candidate  The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.  Assigned (20150224)  None (candidate not yet proposed)    View

Page 20722 of 20943, showing 5 records out of 104715 total, starting on record 103606, ending on 103610

Actions