CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23540  CVE-2007-0183  Candidate  Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20070110)  None (candidate not yet proposed)    View
89076  CVE-2016-2257  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none.  Assigned (20160208)  None (candidate not yet proposed)    View
23796  CVE-2007-0439  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20070123)  None (candidate not yet proposed)    View
89332  CVE-2016-2513  Candidate  The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.  Assigned (20160219)  None (candidate not yet proposed)    View
24052  CVE-2007-0695  Candidate  Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.  Assigned (20070203)  None (candidate not yet proposed)    View

Page 20017 of 20943, showing 5 records out of 104715 total, starting on record 100081, ending on 100085

Actions