CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23276  CVE-2006-7172  Candidate  Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via a leading dotted-quad IP address string in the (1) PC-REMOTE-ADDR HTTP header, which is inserted into $_SERVER["HTTP_PC_REMOTE_ADDR"], or (2) ip parameter.  Assigned (20070320)  None (candidate not yet proposed)    View
88812  CVE-2016-1993  Candidate  HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.  Assigned (20160122)  None (candidate not yet proposed)    View
23532  CVE-2007-0175  Candidate  Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.  Assigned (20070110)  None (candidate not yet proposed)    View
89068  CVE-2016-2249  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none.  Assigned (20160208)  None (candidate not yet proposed)    View
23788  CVE-2007-0431  Candidate  AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060).  Assigned (20070122)  None (candidate not yet proposed)    View

Page 19376 of 20943, showing 5 records out of 104715 total, starting on record 96876, ending on 96880

Actions