CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
18927 | CVE-2006-2823 | Candidate | Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) admin/scart.mdb and possibly (2) admin/scart97.mdb. | Assigned (20060605) | None (candidate not yet proposed) | View | |
84463 | CVE-2015-7186 | Candidate | Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document. | Assigned (20150916) | None (candidate not yet proposed) | View | |
19183 | CVE-2006-3079 | Candidate | Cross-site scripting (XSS) vulnerability in index.cfm in SSPwiz Plus 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter. | Assigned (20060619) | None (candidate not yet proposed) | View | |
84719 | CVE-2015-7442 | Candidate | consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value. | Assigned (20150929) | None (candidate not yet proposed) | View | |
19439 | CVE-2006-3335 | Candidate | Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local users to gain privileges via unknown attack vectors. | Assigned (20060702) | None (candidate not yet proposed) | View |
Page 19008 of 20943, showing 5 records out of 104715 total, starting on record 95036, ending on 95040