CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12803 | CVE-2005-1597 | Candidate | Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter. | Assigned (20050516) | None (candidate not yet proposed) | View | |
78339 | CVE-2015-1062 | Candidate | MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app. | Assigned (20150116) | None (candidate not yet proposed) | View | |
13059 | CVE-2005-1853 | Candidate | gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges. | Assigned (20050606) | None (candidate not yet proposed) | View | |
78595 | CVE-2015-1318 | Candidate | The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container). | Assigned (20150122) | None (candidate not yet proposed) | View | |
13315 | CVE-2005-2109 | Candidate | wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use. | Assigned (20050701) | None (candidate not yet proposed) | View |
Page 258 of 20943, showing 5 records out of 104715 total, starting on record 1286, ending on 1290