CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
22289 | CVE-2006-6185 | Candidate | Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php. | Assigned (20061130) | None (candidate not yet proposed) | View | |
87825 | CVE-2016-10304 | Candidate | The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788. | Assigned (20170329) | None (candidate not yet proposed) | View | |
22545 | CVE-2006-6441 | Candidate | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternate boot media, as demonstrated by a USB thumb drive. | Assigned (20061209) | None (candidate not yet proposed) | View | |
88081 | CVE-2016-1262 | Candidate | Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application Layer Gateway (RTSP ALG) is enabled, allow remote attackers to cause a denial of service (flowd crash) via a crafted RTSP packet. | Assigned (20151230) | None (candidate not yet proposed) | View | |
22801 | CVE-2006-6697 | Candidate | CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter. | Assigned (20061221) | None (candidate not yet proposed) | View |
Page 1404 of 20943, showing 5 records out of 104715 total, starting on record 7016, ending on 7020