CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17647  CVE-2006-1543  Candidate  Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.  Assigned (20060330)  None (candidate not yet proposed)    View
83183  CVE-2015-5906  Candidate  The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that character.  Assigned (20150806)  None (candidate not yet proposed)    View
17903  CVE-2006-1799  Candidate  censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.  Assigned (20060417)  None (candidate not yet proposed)    View
83439  CVE-2015-6162  Candidate  Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6152.  Assigned (20150814)  None (candidate not yet proposed)    View
18159  CVE-2006-2055  Candidate  Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.  Assigned (20060426)  None (candidate not yet proposed)    View

Page 19006 of 20943, showing 5 records out of 104715 total, starting on record 95026, ending on 95030

Actions