CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17140  CVE-2006-1036  Candidate  Multiple unspecified vulnerabilities in the Oracle Diagnostics module 2.2 and earlier have unknown impact and attack vectors, related to "permissions."  Assigned (20060307)  None (candidate not yet proposed)    View
82676  CVE-2015-5399  Candidate  Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.  Assigned (20150706)  None (candidate not yet proposed)    View
17396  CVE-2006-1292  Candidate  Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.  Assigned (20060319)  None (candidate not yet proposed)    View
82932  CVE-2015-5655  Candidate  The Adways Party Track SDK before 1.6.6 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20150724)  None (candidate not yet proposed)    View
17652  CVE-2006-1548  Candidate  Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.  Assigned (20060330)  None (candidate not yet proposed)    View

Page 20004 of 20943, showing 5 records out of 104715 total, starting on record 100016, ending on 100020

Actions