CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20464  CVE-2006-4360  Candidate  Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20060825)  None (candidate not yet proposed)    View
86000  CVE-2015-8723  Candidate  The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationship between the total length and the capture length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.  Assigned (20160103)  None (candidate not yet proposed)    View
20720  CVE-2006-4616  Candidate  SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception.  Assigned (20060906)  None (candidate not yet proposed)    View
86256  CVE-2015-8979  Candidate  Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a long string sent to TCP port 4242.  Assigned (20161217)  None (candidate not yet proposed)    View
20976  CVE-2006-4872  Candidate  SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.  Assigned (20060919)  None (candidate not yet proposed)    View

Page 19700 of 20943, showing 5 records out of 104715 total, starting on record 98496, ending on 98500

Actions