CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17639  CVE-2006-1535  Candidate  Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.  Assigned (20060330)  None (candidate not yet proposed)    View
83175  CVE-2015-5898  Candidate  CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.  Assigned (20150806)  None (candidate not yet proposed)    View
17895  CVE-2006-1791  Candidate  Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails.  Assigned (20060414)  None (candidate not yet proposed)    View
83431  CVE-2015-6154  Candidate  Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6150.  Assigned (20150814)  None (candidate not yet proposed)    View
18151  CVE-2006-2047  Candidate  Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows remote attackers to obtain sensitive information via an invalid (1) secondary, (2) PageNum_Results, (3) category, or (4) keywords parameter in (a) Results.cfm; or an invalid (5) ProdID parameter in (b) Details.cfm; which reveal the path in various error messages. NOTE: the behavior for the category, keywords, and ProdID parameters might be resultant from SQL injection.  Assigned (20060426)  None (candidate not yet proposed)    View

Page 19002 of 20943, showing 5 records out of 104715 total, starting on record 95006, ending on 95010

Actions