CVE List

Id CVE No. Status Description Phase Votes Comments Actions
82942  CVE-2015-5665  Candidate  Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function.  Assigned (20150724)  None (candidate not yet proposed)    View
17662  CVE-2006-1558  Candidate  Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20060331)  None (candidate not yet proposed)    View
83198  CVE-2015-5921  Candidate  WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.  Assigned (20150806)  None (candidate not yet proposed)    View
17918  CVE-2006-1814  Candidate  NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.  Assigned (20060417)  None (candidate not yet proposed)    View
83454  CVE-2015-6177  Candidate  Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."  Assigned (20150814)  None (candidate not yet proposed)    View

Page 20199 of 20943, showing 5 records out of 104715 total, starting on record 100991, ending on 100995

Actions