CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
81409 | CVE-2015-4132 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150528) | None (candidate not yet proposed) | View | |
16129 | CVE-2006-0025 | Candidate | Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size. | Assigned (20051130) | None (candidate not yet proposed) | View | |
81665 | CVE-2015-4388 | Candidate | Cross-site scripting (XSS) vulnerability in the Current Search Links module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the keywords passed by the user to the list" option is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted search query. | Assigned (20150605) | None (candidate not yet proposed) | View | |
16385 | CVE-2006-0281 | Candidate | Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01. | Assigned (20060118) | None (candidate not yet proposed) | View | |
81921 | CVE-2015-4644 | Candidate | The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352. | Assigned (20150618) | None (candidate not yet proposed) | View |
Page 135 of 20943, showing 5 records out of 104715 total, starting on record 671, ending on 675