CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78335  CVE-2015-1058  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to admin/fields/ajax_fields/, (3) name property in a basicInfo JSON object to admin/tools/create_theme, (4) data[Link][link_title] parameter to admin/links/links/add, or (5) data[ForumTopic][subject] parameter to forums/off-topic/new.  Assigned (20150116)  None (candidate not yet proposed)    View
13055  CVE-2005-1849  Candidate  inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.  Assigned (20050606)  None (candidate not yet proposed)    View
78591  CVE-2015-1314  Candidate  The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login, which might allow physically proximate users to obtain banking account numbers and balances.  Assigned (20150122)  None (candidate not yet proposed)    View
13311  CVE-2005-2105  Candidate  Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.  Assigned (20050701)  None (candidate not yet proposed)    View
78847  CVE-2015-1570  Candidate  The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.  Assigned (20150210)  None (candidate not yet proposed)    View

Page 20882 of 20943, showing 5 records out of 104715 total, starting on record 104406, ending on 104410

Actions