CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22549  CVE-2006-6445  Candidate  Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.  Assigned (20061210)  None (candidate not yet proposed)    View
88085  CVE-2016-1266  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20151230)  None (candidate not yet proposed)    View
22805  CVE-2006-6701  Candidate  Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail.  Assigned (20061222)  None (candidate not yet proposed)    View
88341  CVE-2016-1522  Candidate  Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.  Assigned (20160107)  None (candidate not yet proposed)    View
23061  CVE-2006-6957  Candidate  PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_framework] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576 and CVE-2006-3107, but the vectors are different.  Assigned (20070129)  None (candidate not yet proposed)    View

Page 1685 of 20943, showing 5 records out of 104715 total, starting on record 8421, ending on 8425

Actions