CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17386  CVE-2006-1282  Candidate  CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages.  Assigned (20060318)  None (candidate not yet proposed)    View
82922  CVE-2015-5645  Candidate  ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.  Assigned (20150724)  None (candidate not yet proposed)    View
17642  CVE-2006-1538  Candidate  The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus.  Assigned (20060330)  None (candidate not yet proposed)    View
83178  CVE-2015-5901  Candidate  The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.  Assigned (20150806)  None (candidate not yet proposed)    View
17898  CVE-2006-1794  Candidate  SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).  Assigned (20060417)  None (candidate not yet proposed)    View

Page 18608 of 20943, showing 5 records out of 104715 total, starting on record 93036, ending on 93040

Actions