CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
17428 | CVE-2006-1324 | Candidate | Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated. | Assigned (20060320) | None (candidate not yet proposed) | View | |
82964 | CVE-2015-5687 | Candidate | system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie. | Assigned (20150727) | None (candidate not yet proposed) | View | |
17684 | CVE-2006-1580 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp. | Assigned (20060402) | None (candidate not yet proposed) | View | |
83220 | CVE-2015-5943 | Candidate | SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a crafted app. | Assigned (20150806) | None (candidate not yet proposed) | View | |
17940 | CVE-2006-1836 | Candidate | Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | Assigned (20060419) | None (candidate not yet proposed) | View |
Page 1600 of 20943, showing 5 records out of 104715 total, starting on record 7996, ending on 8000