CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
22515 | CVE-2006-6411 | Candidate | PhoneCtrl.exe in Linksys WIP 330 Wireless-G IP Phone 1.00.06A allows remote attackers to cause a denial of service (crash) via a TCP SYN scan, as demonstrated using TCP ports 1-65535 with nmap. | Assigned (20061209) | None (candidate not yet proposed) | View | |
88051 | CVE-2016-1232 | Candidate | The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack. | Assigned (20151227) | None (candidate not yet proposed) | View | |
22771 | CVE-2006-6667 | Candidate | Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nick_mod or (2) nick parameter to (a) repass.php or (b) verify.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20061220) | None (candidate not yet proposed) | View | |
88307 | CVE-2016-1488 | Candidate | Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | Assigned (20160104) | None (candidate not yet proposed) | View | |
23027 | CVE-2006-6923 | Candidate | SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the tk parameter. | Assigned (20070112) | None (candidate not yet proposed) | View |
Page 18812 of 20943, showing 5 records out of 104715 total, starting on record 94056, ending on 94060