CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20225  CVE-2006-4121  Candidate  PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.  Assigned (20060814)  None (candidate not yet proposed)    View
85761  CVE-2015-8484  Candidate  Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-1152.  Assigned (20151207)  None (candidate not yet proposed)    View
20481  CVE-2006-4377  Candidate  Multiple SQL injection vulnerabilities in Guder und Koch Netzwerktechnik Eichhorn Portal allow remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly including the (1) profil_nr and (2) sprache parameters in the main portion of the portal, the (3) suchstring field in suchForm in the main portion of the portal, the (4) GaleryKey and (5) Breadcrumbs parameters in the gallerie module, and the (6) GGBNSaction parameter in the ggbns module.  Assigned (20060825)  None (candidate not yet proposed)    View
86017  CVE-2015-8740  Candidate  The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.  Assigned (20160103)  None (candidate not yet proposed)    View
20737  CVE-2006-4633  Candidate  index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter.  Assigned (20060908)  None (candidate not yet proposed)    View

Page 1265 of 20943, showing 5 records out of 104715 total, starting on record 6321, ending on 6325

Actions