CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21996  CVE-2006-5892  Candidate  SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20061114)  None (candidate not yet proposed)    View
87532  CVE-2016-10038  Candidate  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.  Assigned (20161224)  None (candidate not yet proposed)    View
22252  CVE-2006-6148  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp in JiRos Links Manager allow remote attackers to inject arbitrary web script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4) lDescription parameters. NOTE: some of these details are obtained from third party information.  Assigned (20061128)  None (candidate not yet proposed)    View
87788  CVE-2016-10270  Candidate  LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and libtiff/tif_read.c:523:22.  Assigned (20170324)  None (candidate not yet proposed)    View
22508  CVE-2006-6404  Candidate  INNOVATION Data Processing FDR/UPSTREAM 3.3.0 (GA Oct 2003) allows remote attackers to cause a denial of service (service outage) via a sequence of TCP SYN packets to many ports, as demonstrated using nmap. NOTE: the vendor"s testing reportedly found that no denial of service occurred.  Assigned (20061209)  None (candidate not yet proposed)    View

Page 19374 of 20943, showing 5 records out of 104715 total, starting on record 96866, ending on 96870

Actions