CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20215  CVE-2006-4111  Candidate  Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.  Assigned (20060814)  None (candidate not yet proposed)    View
85751  CVE-2015-8474  Candidate  Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.  Assigned (20151204)  None (candidate not yet proposed)    View
20471  CVE-2006-4367  Candidate  SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote attackers to execute arbitrary SQL commands via the start parameter.  Assigned (20060825)  None (candidate not yet proposed)    View
86007  CVE-2015-8730  Candidate  epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted packet.  Assigned (20160103)  None (candidate not yet proposed)    View
20727  CVE-2006-4623  Candidate  The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.  Assigned (20060907)  None (candidate not yet proposed)    View

Page 20257 of 20943, showing 5 records out of 104715 total, starting on record 101281, ending on 101285

Actions