CVE List

Id CVE No. Status Description Phase Votes Comments Actions
16128  CVE-2006-0024  Candidate  Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.  Assigned (20051130)  None (candidate not yet proposed)    View
81664  CVE-2015-4387  Candidate  Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source.  Assigned (20150605)  None (candidate not yet proposed)    View
16384  CVE-2006-0280  Candidate  Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.  Assigned (20060118)  None (candidate not yet proposed)    View
81920  CVE-2015-4643  Candidate  Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.  Assigned (20150618)  None (candidate not yet proposed)    View
16640  CVE-2006-0536  Candidate  Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. NOTE: some sources say that the affected parameter is "date," but the demonstration URL shows that it is "sort".  Assigned (20060203)  None (candidate not yet proposed)    View

Page 1181 of 20943, showing 5 records out of 104715 total, starting on record 5901, ending on 5905

Actions