CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17676  CVE-2006-1572  Candidate  SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action.  Assigned (20060331)  None (candidate not yet proposed)    View
83212  CVE-2015-5935  Candidate  ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5936, CVE-2015-5937, and CVE-2015-5939.  Assigned (20150806)  None (candidate not yet proposed)    View
17932  CVE-2006-1828  Candidate  SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.  Assigned (20060419)  None (candidate not yet proposed)    View
83468  CVE-2015-6191  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150814)  None (candidate not yet proposed)    View
18188  CVE-2006-2084  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php.  Assigned (20060428)  None (candidate not yet proposed)    View

Page 1593 of 20943, showing 5 records out of 104715 total, starting on record 7961, ending on 7965

Actions