CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
86513 | CVE-2016-0217 | Candidate | IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim"s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim"s cookie-based authentication credentials. | Assigned (20151208) | None (candidate not yet proposed) | View | |
21233 | CVE-2006-5129 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) the message parameter, and possibly other parameters, in module/shout/jafshout.php (aka the shoutbox); and (2) the message body in a forum post in module/forum/topicwin.php, related to the name, email, title, date, ldate, and lname variables. | Assigned (20061002) | None (candidate not yet proposed) | View | |
86769 | CVE-2016-0473 | Candidate | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via unknown vectors related to Fluid Core. | Assigned (20151209) | None (candidate not yet proposed) | View | |
21489 | CVE-2006-5385 | Candidate | PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | Assigned (20061018) | None (candidate not yet proposed) | View | |
87025 | CVE-2016-0729 | Candidate | Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document. | Assigned (20151216) | None (candidate not yet proposed) | View |
Page 19779 of 20943, showing 5 records out of 104715 total, starting on record 98891, ending on 98895