CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
19698 | CVE-2006-3594 | Candidate | Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP request, aka bug CSCsd96542. | Assigned (20060714) | None (candidate not yet proposed) | View | |
85234 | CVE-2015-7957 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2015. Notes: none. | Assigned (20151023) | None (candidate not yet proposed) | View | |
19954 | CVE-2006-3850 | Candidate | ** DISPUTED ** PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected. | Assigned (20060725) | None (candidate not yet proposed) | View | |
85490 | CVE-2015-8213 | Candidate | The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY. | Assigned (20151114) | None (candidate not yet proposed) | View | |
20210 | CVE-2006-4106 | Candidate | Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title. | Assigned (20060814) | None (candidate not yet proposed) | View |
Page 19854 of 20943, showing 5 records out of 104715 total, starting on record 99266, ending on 99270