CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81655  CVE-2015-4378  Candidate  Cross-site scripting (XSS) vulnerability in the Crumbs module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with the "Administer Crumbs" permission to inject arbitrary web script or HTML via a custom breadcrumb separator.  Assigned (20150605)  None (candidate not yet proposed)    View
16375  CVE-2006-0271  Candidate  Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions.  Assigned (20060118)  None (candidate not yet proposed)    View
81911  CVE-2015-4634  Candidate  SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.  Assigned (20150616)  None (candidate not yet proposed)    View
16631  CVE-2006-0527  Candidate  BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.  Assigned (20060202)  None (candidate not yet proposed)    View
82167  CVE-2015-4890  Candidate  Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Replication.  Assigned (20150624)  None (candidate not yet proposed)    View

Page 20234 of 20943, showing 5 records out of 104715 total, starting on record 101166, ending on 101170

Actions