CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88051  CVE-2016-1232  Candidate  The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.  Assigned (20151227)  None (candidate not yet proposed)    View
22771  CVE-2006-6667  Candidate  Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nick_mod or (2) nick parameter to (a) repass.php or (b) verify.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20061220)  None (candidate not yet proposed)    View
88307  CVE-2016-1488  Candidate  Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.  Assigned (20160104)  None (candidate not yet proposed)    View
23027  CVE-2006-6923  Candidate  SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the tk parameter.  Assigned (20070112)  None (candidate not yet proposed)    View
88563  CVE-2016-1744  Candidate  The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1743.  Assigned (20160113)  None (candidate not yet proposed)    View

Page 19332 of 20943, showing 5 records out of 104715 total, starting on record 96656, ending on 96660

Actions