CVE List

Id CVE No. Status Description Phase Votes Comments Actions
84494  CVE-2015-7217  Candidate  The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.  Assigned (20150916)  None (candidate not yet proposed)    View
19214  CVE-2006-3110  Candidate  Cross-site scripting (XSS) vulnerability in main.php in Chipmailer 1.09 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) betreff, (3) mail, and (4) text parameters.  Assigned (20060620)  None (candidate not yet proposed)    View
84750  CVE-2015-7473  Candidate  runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.  Assigned (20150929)  None (candidate not yet proposed)    View
19470  CVE-2006-3366  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder "messenger" was never available to the general public...".  Assigned (20060706)  None (candidate not yet proposed)    View
85006  CVE-2015-7729  Candidate  Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitrary XSJS code via unspecified vectors, aka SAP Security Note 2153892.  Assigned (20151006)  None (candidate not yet proposed)    View

Page 1528 of 20943, showing 5 records out of 104715 total, starting on record 7636, ending on 7640

Actions