CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15874  CVE-2005-4670  Candidate  Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.  Assigned (20060127)  None (candidate not yet proposed)    View
81410  CVE-2015-4133  Candidate  Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.  Assigned (20150528)  None (candidate not yet proposed)    View
16130  CVE-2006-0026  Candidate  Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).  Assigned (20051130)  None (candidate not yet proposed)    View
81666  CVE-2015-4389  Candidate  The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission.  Assigned (20150605)  None (candidate not yet proposed)    View
16386  CVE-2006-0282  Candidate  Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.  Assigned (20060118)  None (candidate not yet proposed)    View

Page 183 of 20943, showing 5 records out of 104715 total, starting on record 911, ending on 915

Actions