CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88307  CVE-2016-1488  Candidate  Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.  Assigned (20160104)  None (candidate not yet proposed)    View
23027  CVE-2006-6923  Candidate  SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the tk parameter.  Assigned (20070112)  None (candidate not yet proposed)    View
88563  CVE-2016-1744  Candidate  The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1743.  Assigned (20160113)  None (candidate not yet proposed)    View
23283  CVE-2006-7179  Candidate  ieee80211_input.c in MadWifi before 0.9.3 does not properly process Channel Switch Announcement Information Elements (CSA IEs), which allows remote attackers to cause a denial of service (loss of communication) via a Channel Switch Count less than or equal to one, triggering a channel change.  Assigned (20070329)  None (candidate not yet proposed)    View
88819  CVE-2016-2000  Candidate  HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.  Assigned (20160122)  None (candidate not yet proposed)    View

Page 19936 of 20943, showing 5 records out of 104715 total, starting on record 99676, ending on 99680

Actions