CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
80646 | CVE-2015-3369 | Candidate | Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a term name in a block. | Assigned (20150421) | None (candidate not yet proposed) | View | |
15366 | CVE-2005-4162 | Candidate | Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter. | Assigned (20051211) | None (candidate not yet proposed) | View | |
80902 | CVE-2015-3625 | Candidate | The NVIDIA GPU driver for FreeBSD R352 before 352.09, 346 before 346.72, R349 before 349.16, R343 before 343.36, R340 before 340.76, R337 before 337.25, R334 before 334.21, R331 before 331.113, and R304 before 304.125 allows local users with certain permissions to read or write arbitrary kernel memory via unspecified vectors that trigger an untrusted pointer dereference. | Assigned (20150430) | None (candidate not yet proposed) | View | |
15622 | CVE-2005-4418 | Candidate | util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities. | Assigned (20051220) | None (candidate not yet proposed) | View | |
81158 | CVE-2015-3881 | Candidate | Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml. | Assigned (20150512) | None (candidate not yet proposed) | View |
Page 507 of 20943, showing 5 records out of 104715 total, starting on record 2531, ending on 2535