CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81638  CVE-2015-4361  Candidate  Cross-site request forgery (CSRF) vulnerability in the Registration codes module before 6.x-1.6 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete registration codes via unspecified vectors.  Assigned (20150605)  None (candidate not yet proposed)    View
16358  CVE-2006-0254  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.  Assigned (20060118)  None (candidate not yet proposed)    View
81894  CVE-2015-4617  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150616)  None (candidate not yet proposed)    View
16614  CVE-2006-0510  Candidate  SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.  Assigned (20060201)  None (candidate not yet proposed)    View
82150  CVE-2015-4873  Candidate  Unspecified vulnerability in the Database Scheduler component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.  Assigned (20150624)  None (candidate not yet proposed)    View

Page 18898 of 20943, showing 5 records out of 104715 total, starting on record 94486, ending on 94490

Actions