CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18710  CVE-2006-2606  Candidate  Cross-site scripting (XSS) vulnerability in Chatty, possibly 1.0.2 and other versions, allows remote attackers to inject arbitrary web script or HTML via the username.  Assigned (20060525)  None (candidate not yet proposed)    View
84246  CVE-2015-6969  Candidate  Cross-site scripting (XSS) vulnerability in js/2k11.min.js in the 2k11 theme in Serendipity before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via a user name in a comment, which is not properly handled in a Reply link.  Assigned (20150916)  None (candidate not yet proposed)    View
18966  CVE-2006-2862  Candidate  SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter.  Assigned (20060606)  None (candidate not yet proposed)    View
84502  CVE-2015-7225  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150917)  None (candidate not yet proposed)    View
19222  CVE-2006-3118  Candidate  spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary file before use, which could cause conflicts with other programs that use the same filename, but this is not a distinct issue.  Assigned (20060621)  None (candidate not yet proposed)    View

Page 1756 of 20943, showing 5 records out of 104715 total, starting on record 8776, ending on 8780

Actions