CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
23540 | CVE-2007-0183 | Candidate | Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20070110) | None (candidate not yet proposed) | View | |
89076 | CVE-2016-2257 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none. | Assigned (20160208) | None (candidate not yet proposed) | View | |
23796 | CVE-2007-0439 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20070123) | None (candidate not yet proposed) | View | |
89332 | CVE-2016-2513 | Candidate | The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests. | Assigned (20160219) | None (candidate not yet proposed) | View | |
24052 | CVE-2007-0695 | Candidate | Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions. | Assigned (20070203) | None (candidate not yet proposed) | View |
Page 20014 of 20943, showing 5 records out of 104715 total, starting on record 100066, ending on 100070