CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
83686 | CVE-2015-6409 | Candidate | Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419. | Assigned (20150817) | None (candidate not yet proposed) | View | |
18406 | CVE-2006-2302 | Candidate | SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field. | Assigned (20060511) | None (candidate not yet proposed) | View | |
83942 | CVE-2015-6665 | Candidate | Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag. | Assigned (20150824) | None (candidate not yet proposed) | View | |
18662 | CVE-2006-2558 | Candidate | Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the User-Agent (useragent) header in an HTTP request, which is not filtered when the log files are viewed. | Assigned (20060523) | None (candidate not yet proposed) | View | |
84198 | CVE-2015-6921 | Candidate | Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150911) | None (candidate not yet proposed) | View |
Page 18886 of 20943, showing 5 records out of 104715 total, starting on record 94426, ending on 94430