CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17408  CVE-2006-1304  Candidate  Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."  Assigned (20060320)  None (candidate not yet proposed)    View
82944  CVE-2015-5667  Candidate  Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.  Assigned (20150724)  None (candidate not yet proposed)    View
17664  CVE-2006-1560  Candidate  Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts. NOTE: portions of the description details are obtained from third party information.  Assigned (20060331)  None (candidate not yet proposed)    View
83200  CVE-2015-5923  Candidate  Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.  Assigned (20150806)  None (candidate not yet proposed)    View
17920  CVE-2006-1816  Candidate  PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.  Assigned (20060417)  None (candidate not yet proposed)    View

Page 1183 of 20943, showing 5 records out of 104715 total, starting on record 5911, ending on 5915

Actions