CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79366  CVE-2015-2089  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin 2.0.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (XSS) attacks via the (2) csj_width, (3) csj_height, (4) csj_sleep, (5) csj_fade, or (6) upload_image parameter in the thisismyurl_csj.php page to wp-admin/options-general.php.  Assigned (20150226)  None (candidate not yet proposed)    View
14086  CVE-2005-2880  Candidate  Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (2) LocationID parameter to week.php.  Assigned (20050914)  None (candidate not yet proposed)    View
79622  CVE-2015-2345  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150318)  None (candidate not yet proposed)    View
14342  CVE-2005-3136  Candidate  Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.  Assigned (20051004)  None (candidate not yet proposed)    View
79878  CVE-2015-2601  Candidate  Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, JRockit R28.3.6, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.  Assigned (20150320)  None (candidate not yet proposed)    View

Page 505 of 20943, showing 5 records out of 104715 total, starting on record 2521, ending on 2525

Actions