CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17418  CVE-2006-1314  Candidate  Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.  Assigned (20060320)  None (candidate not yet proposed)    View
82954  CVE-2015-5677  Candidate  bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.  Assigned (20150726)  None (candidate not yet proposed)    View
17674  CVE-2006-1570  Candidate  Cross-site scripting (XSS) vulnerability in Esqlanelapse 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  Assigned (20060331)  None (candidate not yet proposed)    View
83210  CVE-2015-5933  Candidate  Audio in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, a different vulnerability than CVE-2015-5934.  Assigned (20150806)  None (candidate not yet proposed)    View
17930  CVE-2006-1826  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.  Assigned (20060417)  None (candidate not yet proposed)    View

Page 1435 of 20943, showing 5 records out of 104715 total, starting on record 7171, ending on 7175

Actions