CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13053  CVE-2005-1847  Candidate  Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.  Assigned (20050603)  None (candidate not yet proposed)    View
78589  CVE-2015-1312  Candidate  The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and possibly have other unspecified impact via unknown vectors, aka SAP Note 2000401. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20150122)  None (candidate not yet proposed)    View
13309  CVE-2005-2103  Candidate  Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.  Assigned (20050630)  None (candidate not yet proposed)    View
78845  CVE-2015-1568  Candidate  Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote attackers to hijack the authentication of users with the "edit gd infinite scroll settings" permission for requests that delete settings via unspecified vectors.  Assigned (20150209)  None (candidate not yet proposed)    View
13565  CVE-2005-2359  Candidate  The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.  Assigned (20050726)  None (candidate not yet proposed)    View

Page 20723 of 20943, showing 5 records out of 104715 total, starting on record 103611, ending on 103615

Actions