CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87531  CVE-2016-10037  Candidate  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.  Assigned (20161224)  None (candidate not yet proposed)    View
22251  CVE-2006-6147  Candidate  Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.  Assigned (20061128)  None (candidate not yet proposed)    View
87787  CVE-2016-1027  Candidate  Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.  Assigned (20151222)  None (candidate not yet proposed)    View
22507  CVE-2006-6403  Candidate  mystats.php in MyStats 1.0.8 and earlier allows remote attackers to obtain the installation path via (1) details and (2) by array parameters, probably resulting in a path disclosure in an error message.  Assigned (20061209)  None (candidate not yet proposed)    View
88043  CVE-2016-1224  Candidate  CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.  Assigned (20151226)  None (candidate not yet proposed)    View

Page 19294 of 20943, showing 5 records out of 104715 total, starting on record 96466, ending on 96470

Actions