CVE List

Id CVE No. Status Description Phase Votes Comments Actions
85996  CVE-2015-8719  Candidate  The dissect_dns_answer function in epan/dissectors/packet-dns.c in the DNS dissector in Wireshark 1.12.x before 1.12.9 mishandles the EDNS0 Client Subnet option, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.  Assigned (20160103)  None (candidate not yet proposed)    View
20716  CVE-2006-4612  Candidate  SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands via the RepId parameter.  Assigned (20060906)  None (candidate not yet proposed)    View
86252  CVE-2015-8975  Candidate  Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20161117)  None (candidate not yet proposed)    View
20972  CVE-2006-4868  Candidate  Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.  Assigned (20060919)  None (candidate not yet proposed)    View
86508  CVE-2016-0212  Candidate  Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0213 and CVE-2016-0216.  Assigned (20151208)  None (candidate not yet proposed)    View

Page 19393 of 20943, showing 5 records out of 104715 total, starting on record 96961, ending on 96965

Actions