CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
16884 | CVE-2006-0780 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters. | Assigned (20060219) | None (candidate not yet proposed) | View | |
82420 | CVE-2015-5143 | Candidate | The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys. | Assigned (20150629) | None (candidate not yet proposed) | View | |
17140 | CVE-2006-1036 | Candidate | Multiple unspecified vulnerabilities in the Oracle Diagnostics module 2.2 and earlier have unknown impact and attack vectors, related to "permissions." | Assigned (20060307) | None (candidate not yet proposed) | View | |
82676 | CVE-2015-5399 | Candidate | Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment. | Assigned (20150706) | None (candidate not yet proposed) | View | |
17396 | CVE-2006-1292 | Candidate | Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php. | Assigned (20060319) | None (candidate not yet proposed) | View |
Page 20013 of 20943, showing 5 records out of 104715 total, starting on record 100061, ending on 100065