CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81409  CVE-2015-4132  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150528)  None (candidate not yet proposed)    View
16129  CVE-2006-0025  Candidate  Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.  Assigned (20051130)  None (candidate not yet proposed)    View
81665  CVE-2015-4388  Candidate  Cross-site scripting (XSS) vulnerability in the Current Search Links module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the keywords passed by the user to the list" option is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted search query.  Assigned (20150605)  None (candidate not yet proposed)    View
16385  CVE-2006-0281  Candidate  Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01.  Assigned (20060118)  None (candidate not yet proposed)    View
81921  CVE-2015-4644  Candidate  The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.  Assigned (20150618)  None (candidate not yet proposed)    View

Page 135 of 20943, showing 5 records out of 104715 total, starting on record 671, ending on 675

Actions