CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
80648 | CVE-2015-3371 | Candidate | Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter. | Assigned (20150421) | None (candidate not yet proposed) | View | |
15368 | CVE-2005-4164 | Candidate | SQL injection vulnerability in view.php in PHP-addressbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20051211) | None (candidate not yet proposed) | View | |
80904 | CVE-2015-3627 | Candidate | Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image. | Assigned (20150430) | None (candidate not yet proposed) | View | |
15624 | CVE-2005-4420 | Candidate | Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm. | Assigned (20051220) | None (candidate not yet proposed) | View | |
81160 | CVE-2015-3883 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keywords] parameter to index.php/users page; the (2) "Name of application" on index.php/configuration; (3) a new project name on index.php/projects; (4) the task name on index.php/tasks; (5) ticket name on index.php/tickets; (6) discussion name on index.php/discussions; (7) report name on index.php/projectReports; or (8) event name on index.php/scheduler/personal. | Assigned (20150512) | None (candidate not yet proposed) | View |
Page 662 of 20943, showing 5 records out of 104715 total, starting on record 3306, ending on 3310