CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18930  CVE-2006-2826  Candidate  SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie.  Assigned (20060605)  None (candidate not yet proposed)    View
84466  CVE-2015-7189  Candidate  Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.  Assigned (20150916)  None (candidate not yet proposed)    View
19186  CVE-2006-3082  Candidate  parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.  Assigned (20060619)  None (candidate not yet proposed)    View
84722  CVE-2015-7445  Candidate  IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.x before 1.0.0.4, when guest access is configured, allow remote authenticated users to obtain sensitive information by reading error messages in responses.  Assigned (20150929)  None (candidate not yet proposed)    View
19442  CVE-2006-3338  Candidate  Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.  Assigned (20060703)  None (candidate not yet proposed)    View

Page 19850 of 20943, showing 5 records out of 104715 total, starting on record 99246, ending on 99250

Actions