CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
19192 | CVE-2006-3088 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Car Classifieds allows remote attackers to inject arbitrary web script or HTML via the make_id parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | Assigned (20060619) | None (candidate not yet proposed) | View | |
84728 | CVE-2015-7451 | Candidate | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | Assigned (20150929) | None (candidate not yet proposed) | View | |
19448 | CVE-2006-3344 | Candidate | Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play UPnP/1.0 component. | Assigned (20060703) | None (candidate not yet proposed) | View | |
84984 | CVE-2015-7707 | Candidate | Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. | Assigned (20151005) | None (candidate not yet proposed) | View | |
19704 | CVE-2006-3600 | Candidate | Multiple stack-based buffer overflows in the LookupTRM::lookup function in libtunepimp (TunePimp) 0.4.2 allow remote user-assisted attackers to cause a denial of service (application crash) and possibly execute code via a long (1) Album release date (MBE_ReleaseGetDate), (2) data, or (3) error strings. | Assigned (20060714) | None (candidate not yet proposed) | View |
Page 20316 of 20943, showing 5 records out of 104715 total, starting on record 101576, ending on 101580