CVE List

Id CVE No. Status Description Phase Votes Comments Actions
79108  CVE-2015-1831  Candidate  The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.  Assigned (20150217)  None (candidate not yet proposed)    View
13828  CVE-2005-2622  Candidate  Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 6.0.2 allows remote attackers to inject arbitrary web script or HTML via the (1) max or (2) ctg parameter.  Assigned (20050819)  None (candidate not yet proposed)    View
79364  CVE-2015-2087  Candidate  Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.  Assigned (20150226)  None (candidate not yet proposed)    View
14084  CVE-2005-2878  Candidate  Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.  Assigned (20050913)  None (candidate not yet proposed)    View
79620  CVE-2015-2343  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150318)  None (candidate not yet proposed)    View

Page 715 of 20943, showing 5 records out of 104715 total, starting on record 3571, ending on 3575

Actions