CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22798  CVE-2006-6694  Candidate  Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via config.php.  Assigned (20061221)  None (candidate not yet proposed)    View
88334  CVE-2016-1515  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8789. Reason: This candidate is a reservation duplicate of CVE-2015-8789. Notes: All CVE users should reference CVE-2015-8789 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20160107)  None (candidate not yet proposed)    View
23054  CVE-2006-6950  Candidate  Directory traversal vulnerability in Conti FTPServer 1.0 Build 2.8 allows remote attackers to read arbitrary files and list arbitrary directories via a .. (dot dot) in a filename argument.  Assigned (20070122)  None (candidate not yet proposed)    View
88590  CVE-2016-1771  Candidate  The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.  Assigned (20160113)  None (candidate not yet proposed)    View
23310  CVE-2006-7206  Candidate  Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.  Assigned (20070621)  None (candidate not yet proposed)    View

Page 1147 of 20943, showing 5 records out of 104715 total, starting on record 5731, ending on 5735

Actions