CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81159  CVE-2015-3882  Candidate  qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.  Assigned (20150512)  None (candidate not yet proposed)    View
15879  CVE-2005-4675  Candidate  Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary web script or HTML via the c parameter.  Assigned (20060127)  None (candidate not yet proposed)    View
81415  CVE-2015-4138  Candidate  The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator"s cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2015-2855.  Assigned (20150530)  None (candidate not yet proposed)    View
16135  CVE-2006-0031  Candidate  Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.  Assigned (20051130)  None (candidate not yet proposed)    View
81671  CVE-2015-4394  Candidate  The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified vectors.  Assigned (20150605)  None (candidate not yet proposed)    View

Page 588 of 20943, showing 5 records out of 104715 total, starting on record 2936, ending on 2940

Actions