CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20725  CVE-2006-4621  Candidate  PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The lib/config.php vector is already covered by CVE-2006-4531.  Assigned (20060906)  None (candidate not yet proposed)    View
86261  CVE-2015-8984  Candidate  The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read.  Assigned (20170214)  None (candidate not yet proposed)    View
20981  CVE-2006-4877  Candidate  Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via multiple vectors that use the extract function, as demonstrated by the table_prefix parameter in (1) index.php, (2) profile.php, and (3) header.php.  Assigned (20060919)  None (candidate not yet proposed)    View
86517  CVE-2016-0221  Candidate  Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20151208)  None (candidate not yet proposed)    View
21237  CVE-2006-5133  Candidate  Buffer overflow in GuildFTPd 0.999.13 allows remote attackers to have an unknown impact, possibly code execution related to input containing "globbing chars."  Assigned (20061002)  None (candidate not yet proposed)    View

Page 20099 of 20943, showing 5 records out of 104715 total, starting on record 100491, ending on 100495

Actions