CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81919  CVE-2015-4642  Candidate  The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.  Assigned (20150618)  None (candidate not yet proposed)    View
16639  CVE-2006-0535  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20060203)  None (candidate not yet proposed)    View
82175  CVE-2015-4898  Candidate  Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via vectors related to Diagnostics and DMZ.  Assigned (20150624)  None (candidate not yet proposed)    View
16895  CVE-2006-0791  Candidate  PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use.  Assigned (20060219)  None (candidate not yet proposed)    View
82431  CVE-2015-5154  Candidate  Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.  Assigned (20150701)  None (candidate not yet proposed)    View

Page 20277 of 20943, showing 5 records out of 104715 total, starting on record 101381, ending on 101385

Actions