CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17391  CVE-2006-1287  Candidate  Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer.  Assigned (20060319)  None (candidate not yet proposed)    View
82927  CVE-2015-5650  Candidate  Directory traversal vulnerability in AjaXplorer 2.0 allows remote attackers to read arbitrary files via unspecified vectors.  Assigned (20150724)  None (candidate not yet proposed)    View
17647  CVE-2006-1543  Candidate  Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.  Assigned (20060330)  None (candidate not yet proposed)    View
83183  CVE-2015-5906  Candidate  The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that character.  Assigned (20150806)  None (candidate not yet proposed)    View
17903  CVE-2006-1799  Candidate  censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.  Assigned (20060417)  None (candidate not yet proposed)    View

Page 19607 of 20943, showing 5 records out of 104715 total, starting on record 98031, ending on 98035

Actions