CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21991  CVE-2006-5887  Candidate  SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.  Assigned (20061114)  None (candidate not yet proposed)    View
87527  CVE-2016-10033  Candidate  The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property.  Assigned (20161222)  None (candidate not yet proposed)    View
22247  CVE-2006-6143  Candidate  The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.  Assigned (20061128)  None (candidate not yet proposed)    View
87783  CVE-2016-10266  Candidate  LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.  Assigned (20170324)  None (candidate not yet proposed)    View
22503  CVE-2006-6399  Candidate  SQL injection vulnerability in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. NOTE: the provenance of this information is unknown; details are obtained from third party sources.  Assigned (20061207)  None (candidate not yet proposed)    View

Page 18973 of 20943, showing 5 records out of 104715 total, starting on record 94861, ending on 94865

Actions