CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15874 | CVE-2005-4670 | Candidate | Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | Assigned (20060127) | None (candidate not yet proposed) | View | |
81410 | CVE-2015-4133 | Candidate | Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory. | Assigned (20150528) | None (candidate not yet proposed) | View | |
16130 | CVE-2006-0026 | Candidate | Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). | Assigned (20051130) | None (candidate not yet proposed) | View | |
81666 | CVE-2015-4389 | Candidate | The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission. | Assigned (20150605) | None (candidate not yet proposed) | View | |
16386 | CVE-2006-0282 | Candidate | Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component. | Assigned (20060118) | None (candidate not yet proposed) | View |
Page 183 of 20943, showing 5 records out of 104715 total, starting on record 911, ending on 915