CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22805  CVE-2006-6701  Candidate  Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail.  Assigned (20061222)  None (candidate not yet proposed)    View
88341  CVE-2016-1522  Candidate  Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.  Assigned (20160107)  None (candidate not yet proposed)    View
23061  CVE-2006-6957  Candidate  PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_framework] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576 and CVE-2006-3107, but the vectors are different.  Assigned (20070129)  None (candidate not yet proposed)    View
88597  CVE-2016-1778  Candidate  WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.  Assigned (20160113)  None (candidate not yet proposed)    View
23317  CVE-2006-7213  Candidate  Firebird 1.5 allows remote authenticated users without SYSDBA and owner permissions to overwrite a database by creating a database.  Assigned (20070629)  None (candidate not yet proposed)    View

Page 1704 of 20943, showing 5 records out of 104715 total, starting on record 8516, ending on 8520

Actions