CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14345 | CVE-2005-3139 | Candidate | Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set. | Assigned (20051005) | None (candidate not yet proposed) | View | |
79881 | CVE-2015-2604 | Candidate | Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2605, CVE-2015-2606, and CVE-2015-4745. | Assigned (20150320) | None (candidate not yet proposed) | View | |
14601 | CVE-2005-3395 | Candidate | SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter. | Assigned (20051101) | None (candidate not yet proposed) | View | |
80137 | CVE-2015-2860 | Candidate | Directory traversal vulnerability in Avigilon Control Center (ACC) 4 before 4.12.0.54 and 5 before 5.4.2.22 allows remote attackers to read arbitrary files via a crafted help/ URL. | Assigned (20150403) | None (candidate not yet proposed) | View | |
14857 | CVE-2005-3653 | Candidate | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | Assigned (20051118) | None (candidate not yet proposed) | View |
Page 740 of 20943, showing 5 records out of 104715 total, starting on record 3696, ending on 3700