CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18927  CVE-2006-2823  Candidate  Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) admin/scart.mdb and possibly (2) admin/scart97.mdb.  Assigned (20060605)  None (candidate not yet proposed)    View
84463  CVE-2015-7186  Candidate  Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.  Assigned (20150916)  None (candidate not yet proposed)    View
19183  CVE-2006-3079  Candidate  Cross-site scripting (XSS) vulnerability in index.cfm in SSPwiz Plus 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.  Assigned (20060619)  None (candidate not yet proposed)    View
84719  CVE-2015-7442  Candidate  consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value.  Assigned (20150929)  None (candidate not yet proposed)    View
19439  CVE-2006-3335  Candidate  Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local users to gain privileges via unknown attack vectors.  Assigned (20060702)  None (candidate not yet proposed)    View

Page 19008 of 20943, showing 5 records out of 104715 total, starting on record 95036, ending on 95040

Actions