CVE List

Id CVE No. Status Description Phase Votes Comments Actions
16358  CVE-2006-0254  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.  Assigned (20060118)  None (candidate not yet proposed)    View
81894  CVE-2015-4617  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150616)  None (candidate not yet proposed)    View
16614  CVE-2006-0510  Candidate  SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.  Assigned (20060201)  None (candidate not yet proposed)    View
82150  CVE-2015-4873  Candidate  Unspecified vulnerability in the Database Scheduler component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.  Assigned (20150624)  None (candidate not yet proposed)    View
16870  CVE-2006-0766  Candidate  ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs.  Assigned (20060218)  None (candidate not yet proposed)    View

Page 18883 of 20943, showing 5 records out of 104715 total, starting on record 94411, ending on 94415

Actions