CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87831  CVE-2016-1031  Candidate  Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1017.  Assigned (20151222)  None (candidate not yet proposed)    View
22551  CVE-2006-6447  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.  Assigned (20061210)  None (candidate not yet proposed)    View
88087  CVE-2016-1268  Candidate  The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet.  Assigned (20151230)  None (candidate not yet proposed)    View
22807  CVE-2006-6703  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.  Assigned (20061222)  None (candidate not yet proposed)    View
88343  CVE-2016-1524  Candidate  Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.  Assigned (20160107)  None (candidate not yet proposed)    View

Page 1886 of 20943, showing 5 records out of 104715 total, starting on record 9426, ending on 9430

Actions