CVE List

Id CVE No. Status Description Phase Votes Comments Actions
85006  CVE-2015-7729  Candidate  Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitrary XSJS code via unspecified vectors, aka SAP Security Note 2153892.  Assigned (20151006)  None (candidate not yet proposed)    View
19726  CVE-2006-3622  Candidate  The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a " (single quote) in the p parameter, which displays the path in an error message. NOTE: it is not clear whether this is SQL injection or a forced SQL error.  Assigned (20060714)  None (candidate not yet proposed)    View
85262  CVE-2015-7985  Candidate  Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.  Assigned (20151027)  None (candidate not yet proposed)    View
19982  CVE-2006-3878  Candidate  Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.  Assigned (20060726)  None (candidate not yet proposed)    View
85518  CVE-2015-8241  Candidate  The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.  Assigned (20151118)  None (candidate not yet proposed)    View

Page 1142 of 20943, showing 5 records out of 104715 total, starting on record 5706, ending on 5710

Actions