CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78083  CVE-2015-0820  Candidate  Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.  Assigned (20150107)  None (candidate not yet proposed)    View
12803  CVE-2005-1597  Candidate  Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
78339  CVE-2015-1062  Candidate  MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app.  Assigned (20150116)  None (candidate not yet proposed)    View
13059  CVE-2005-1853  Candidate  gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.  Assigned (20050606)  None (candidate not yet proposed)    View
78595  CVE-2015-1318  Candidate  The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).  Assigned (20150122)  None (candidate not yet proposed)    View

Page 262 of 20943, showing 5 records out of 104715 total, starting on record 1306, ending on 1310

Actions