CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12290 | CVE-2005-1084 | Candidate | SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter. | Assigned (20050413) | None (candidate not yet proposed) | View | |
77826 | CVE-2015-0563 | Candidate | epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | Assigned (20150106) | None (candidate not yet proposed) | View | |
12546 | CVE-2005-1340 | Candidate | The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy. | Assigned (20050427) | None (candidate not yet proposed) | View | |
78082 | CVE-2015-0819 | Candidate | The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12802 | CVE-2005-1596 | Candidate | index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter. | Assigned (20050516) | None (candidate not yet proposed) | View |
Page 788 of 20943, showing 5 records out of 104715 total, starting on record 3936, ending on 3940