CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22807  CVE-2006-6703  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.  Assigned (20061222)  None (candidate not yet proposed)    View
88343  CVE-2016-1524  Candidate  Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.  Assigned (20160107)  None (candidate not yet proposed)    View
23063  CVE-2006-6959  Candidate  WebRoot Spy Sweeper 4.5.9 and earlier allows local users to bypass the "Startup-Shield" security restrictions by modifying certain registry keys.  Assigned (20070129)  None (candidate not yet proposed)    View
88599  CVE-2016-1780  Candidate  WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device"s physical environment via a crafted web site.  Assigned (20160113)  None (candidate not yet proposed)    View
23319  CVE-2006-7215  Candidate  The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory page Access (A) bit for a page in certain circumstances involving proximity of the code segment limit to the end of a code page, which has unknown impact and attack vectors on certain operating systems other than OpenBSD, aka AI90.  Assigned (20070703)  None (candidate not yet proposed)    View

Page 1863 of 20943, showing 5 records out of 104715 total, starting on record 9311, ending on 9315

Actions