CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12290  CVE-2005-1084  Candidate  SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.  Assigned (20050413)  None (candidate not yet proposed)    View
77826  CVE-2015-0563  Candidate  epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.  Assigned (20150106)  None (candidate not yet proposed)    View
12546  CVE-2005-1340  Candidate  The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.  Assigned (20050427)  None (candidate not yet proposed)    View
78082  CVE-2015-0819  Candidate  The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.  Assigned (20150107)  None (candidate not yet proposed)    View
12802  CVE-2005-1596  Candidate  index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.  Assigned (20050516)  None (candidate not yet proposed)    View

Page 788 of 20943, showing 5 records out of 104715 total, starting on record 3936, ending on 3940

Actions