CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17649  CVE-2006-1545  Candidate  Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.  Assigned (20060330)  None (candidate not yet proposed)    View
83185  CVE-2015-5908  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150806)  None (candidate not yet proposed)    View
17905  CVE-2006-1801  Candidate  Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.  Assigned (20060417)  None (candidate not yet proposed)    View
83441  CVE-2015-6164  Candidate  Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability."  Assigned (20150814)  None (candidate not yet proposed)    View
18161  CVE-2006-2057  Candidate  Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.  Assigned (20060426)  None (candidate not yet proposed)    View

Page 19776 of 20943, showing 5 records out of 104715 total, starting on record 98876, ending on 98880

Actions