CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21998  CVE-2006-5894  Candidate  Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.  Assigned (20061114)  None (candidate not yet proposed)    View
87534  CVE-2016-1004  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none.  Assigned (20151222)  None (candidate not yet proposed)    View
22254  CVE-2006-6150  Candidate  PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the OWLLIB_ROOT parameter.  Assigned (20061128)  None (candidate not yet proposed)    View
87790  CVE-2016-10272  Candidate  LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "WRITE of size 2048" and libtiff/tif_next.c:64:9.  Assigned (20170324)  None (candidate not yet proposed)    View
22510  CVE-2006-6406  Candidate  Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.  Assigned (20061209)  None (candidate not yet proposed)    View

Page 18933 of 20943, showing 5 records out of 104715 total, starting on record 94661, ending on 94665

Actions