CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22773  CVE-2006-6669  Candidate  Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter.  Assigned (20061220)  None (candidate not yet proposed)    View
88309  CVE-2016-1490  Candidate  The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.  Assigned (20160104)  None (candidate not yet proposed)    View
23029  CVE-2006-6925  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the message title field when submitting an article to articles/edit.php, (2) the message title field when submitting a blog post to blogs/post.php, or (3) the message description field when editing in the Sandbox in wiki/edit.php.  Assigned (20070112)  None (candidate not yet proposed)    View
88565  CVE-2016-1746  Candidate  IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1747.  Assigned (20160113)  None (candidate not yet proposed)    View
23285  CVE-2006-7181  Candidate  ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Morcego CMS 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) fichero parameter to morcegoCMS.php or the (2) path parameter to adodb/adodb.inc.php. NOTE: vector 1 has been disputed by a third party who shows that $fichero can not be controlled by an attacker.  Assigned (20070329)  None (candidate not yet proposed)    View

Page 20090 of 20943, showing 5 records out of 104715 total, starting on record 100446, ending on 100450

Actions