CVE List

Id CVE No. Status Description Phase Votes Comments Actions
80650  CVE-2015-3373  Candidate  The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.  Assigned (20150421)  None (candidate not yet proposed)    View
15370  CVE-2005-4166  Candidate  Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.  Assigned (20051211)  None (candidate not yet proposed)    View
80906  CVE-2015-3629  Candidate  Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.  Assigned (20150501)  None (candidate not yet proposed)    View
15626  CVE-2005-4422  Candidate  Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.  Assigned (20051220)  None (candidate not yet proposed)    View
81162  CVE-2015-3885  Candidate  Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.  Assigned (20150512)  None (candidate not yet proposed)    View

Page 821 of 20943, showing 5 records out of 104715 total, starting on record 4101, ending on 4105

Actions