CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
80651 | CVE-2015-3374 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in the Corner module for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable or (2) disable corners via unspecified vectors. | Assigned (20150421) | None (candidate not yet proposed) | View | |
15371 | CVE-2005-4167 | Candidate | Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php. | Assigned (20051211) | None (candidate not yet proposed) | View | |
80907 | CVE-2015-3630 | Candidate | Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image. | Assigned (20150501) | None (candidate not yet proposed) | View | |
15627 | CVE-2005-4423 | Candidate | Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell." | Assigned (20051220) | None (candidate not yet proposed) | View | |
81163 | CVE-2015-3886 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150512) | None (candidate not yet proposed) | View |
Page 900 of 20943, showing 5 records out of 104715 total, starting on record 4496, ending on 4500