CVE List

Id CVE No. Status Description Phase Votes Comments Actions
89331  CVE-2016-2512  Candidate  The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com@attacker.com.  Assigned (20160219)  None (candidate not yet proposed)    View
24051  CVE-2007-0694  Candidate  Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.  Assigned (20070203)  None (candidate not yet proposed)    View
89587  CVE-2016-2768  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160226)  None (candidate not yet proposed)    View
24307  CVE-2007-0950  Candidate  Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.  Assigned (20070214)  None (candidate not yet proposed)    View
89843  CVE-2016-3024  Candidate  IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.  Assigned (20160309)  None (candidate not yet proposed)    View

Page 19334 of 20943, showing 5 records out of 104715 total, starting on record 96666, ending on 96670

Actions