CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18929  CVE-2006-2825  Candidate  cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user"s own open_basedir directive, but not the main server"s open_basedir directive.  Assigned (20060605)  None (candidate not yet proposed)    View
84465  CVE-2015-7188  Candidate  Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.  Assigned (20150916)  None (candidate not yet proposed)    View
19185  CVE-2006-3081  Candidate  mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.  Assigned (20060619)  None (candidate not yet proposed)    View
84721  CVE-2015-7444  Candidate  The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.  Assigned (20150929)  None (candidate not yet proposed)    View
19441  CVE-2006-3337  Candidate  Cross-site scripting (XSS) vulnerability in frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.  Assigned (20060703)  None (candidate not yet proposed)    View

Page 19778 of 20943, showing 5 records out of 104715 total, starting on record 98886, ending on 98890

Actions