CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
82942 | CVE-2015-5665 | Candidate | Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function. | Assigned (20150724) | None (candidate not yet proposed) | View | |
17662 | CVE-2006-1558 | Candidate | Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Assigned (20060331) | None (candidate not yet proposed) | View | |
83198 | CVE-2015-5921 | Candidate | WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors. | Assigned (20150806) | None (candidate not yet proposed) | View | |
17918 | CVE-2006-1814 | Candidate | NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory. | Assigned (20060417) | None (candidate not yet proposed) | View | |
83454 | CVE-2015-6177 | Candidate | Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." | Assigned (20150814) | None (candidate not yet proposed) | View |
Page 20199 of 20943, showing 5 records out of 104715 total, starting on record 100991, ending on 100995