CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
19426 | CVE-2006-3322 | Candidate | SQL injection vulnerability in includes/functions_logging.php in phpRaid 3.0.5, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the log_hack function. | Assigned (20060630) | None (candidate not yet proposed) | View | |
84962 | CVE-2015-7685 | Candidate | GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php. | Assigned (20151002) | None (candidate not yet proposed) | View | |
19682 | CVE-2006-3578 | Candidate | Directory traversal vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to read arbitrary files via unspecified vectors. | Assigned (20060712) | None (candidate not yet proposed) | View | |
85218 | CVE-2015-7941 | Candidate | libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities. | Assigned (20151022) | None (candidate not yet proposed) | View | |
19938 | CVE-2006-3834 | Candidate | EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors. | Assigned (20060724) | None (candidate not yet proposed) | View |
Page 18619 of 20943, showing 5 records out of 104715 total, starting on record 93091, ending on 93095