CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80648  CVE-2015-3371  Candidate  Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.  Assigned (20150421)  None (candidate not yet proposed)    View
15368  CVE-2005-4164  Candidate  SQL injection vulnerability in view.php in PHP-addressbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20051211)  None (candidate not yet proposed)    View
80904  CVE-2015-3627  Candidate  Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.  Assigned (20150430)  None (candidate not yet proposed)    View
15624  CVE-2005-4420  Candidate  Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.  Assigned (20051220)  None (candidate not yet proposed)    View
81160  CVE-2015-3883  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keywords] parameter to index.php/users page; the (2) "Name of application" on index.php/configuration; (3) a new project name on index.php/projects; (4) the task name on index.php/tasks; (5) ticket name on index.php/tickets; (6) discussion name on index.php/discussions; (7) report name on index.php/projectReports; or (8) event name on index.php/scheduler/personal.  Assigned (20150512)  None (candidate not yet proposed)    View

Page 662 of 20943, showing 5 records out of 104715 total, starting on record 3306, ending on 3310

Actions