CVE List

Id CVE No. Status Description Phase Votes Comments Actions
16884  CVE-2006-0780  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.  Assigned (20060219)  None (candidate not yet proposed)    View
82420  CVE-2015-5143  Candidate  The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.  Assigned (20150629)  None (candidate not yet proposed)    View
17140  CVE-2006-1036  Candidate  Multiple unspecified vulnerabilities in the Oracle Diagnostics module 2.2 and earlier have unknown impact and attack vectors, related to "permissions."  Assigned (20060307)  None (candidate not yet proposed)    View
82676  CVE-2015-5399  Candidate  Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.  Assigned (20150706)  None (candidate not yet proposed)    View
17396  CVE-2006-1292  Candidate  Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.  Assigned (20060319)  None (candidate not yet proposed)    View

Page 20013 of 20943, showing 5 records out of 104715 total, starting on record 100061, ending on 100065

Actions