CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
17939 | CVE-2006-1835 | Candidate | Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter. | Assigned (20060419) | None (candidate not yet proposed) | View | |
83475 | CVE-2015-6198 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150814) | None (candidate not yet proposed) | View | |
18195 | CVE-2006-2091 | Candidate | admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_root parameter, which reveals the path in an error message. | Assigned (20060428) | None (candidate not yet proposed) | View | |
83731 | CVE-2015-6454 | Candidate | Everest PeakHMI before 8.7.0.2, when the video server is used, allows remote attackers to cause a denial of service (incorrect pointer dereference and daemon crash) via a crafted packet. | Assigned (20150817) | None (candidate not yet proposed) | View | |
18451 | CVE-2006-2347 | Candidate | E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via """ characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories. NOTE: this issue might be resultant from SQL injection. | Assigned (20060512) | None (candidate not yet proposed) | View |
Page 1524 of 20943, showing 5 records out of 104715 total, starting on record 7616, ending on 7620