CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78853  CVE-2015-1576  Candidate  Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7) c parameter to u5admin/editor.php; (8) typ parameter to u5admin/meta2.php; or (9) newname parameter to u5admin/rename2.php.  Assigned (20150211)  None (candidate not yet proposed)    View
13573  CVE-2005-2367  Candidate  Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.  Assigned (20050726)  None (candidate not yet proposed)    View
79109  CVE-2015-1832  Candidate  XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.  Assigned (20150217)  None (candidate not yet proposed)    View
13829  CVE-2005-2623  Candidate  ECW-Shop 6.0.2 allows remote attackers to reduce the total cost of their shopping cart by specifying a negative quantity for an item, which causes the price of the item to be subtracted from the total cost.  Assigned (20050819)  None (candidate not yet proposed)    View
79365  CVE-2015-2088  Candidate  Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors.  Assigned (20150226)  None (candidate not yet proposed)    View

Page 424 of 20943, showing 5 records out of 104715 total, starting on record 2116, ending on 2120

Actions