CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20245  CVE-2006-4141  Candidate  SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) sortby and (2) sortorder parameters.  Assigned (20060814)  None (candidate not yet proposed)    View
85781  CVE-2015-8504  Candidate  Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.  Assigned (20151208)  None (candidate not yet proposed)    View
20501  CVE-2006-4397  Candidate  Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access to the original user"s Kerberos tickets.  Assigned (20060828)  None (candidate not yet proposed)    View
86037  CVE-2015-8760  Candidate  The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."  Assigned (20160108)  None (candidate not yet proposed)    View
20757  CVE-2006-4653  Candidate  (1) Amazing Little Poll and (2) Amazing Little Picture Poll store sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password via a direct request for the lp_settings file (lp_settings.inc or lp_settings.php).  Assigned (20060908)  None (candidate not yet proposed)    View

Page 1700 of 20943, showing 5 records out of 104715 total, starting on record 8496, ending on 8500

Actions