CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17913  CVE-2006-1809  Candidate  index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error message.  Assigned (20060417)  None (candidate not yet proposed)    View
83449  CVE-2015-6172  Candidate  Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."  Assigned (20150814)  None (candidate not yet proposed)    View
18169  CVE-2006-2065  Candidate  SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey["language"] variable.  Assigned (20060426)  None (candidate not yet proposed)    View
83705  CVE-2015-6428  Candidate  Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.  Assigned (20150817)  None (candidate not yet proposed)    View
18425  CVE-2006-2321  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Ideal Science Ideal BB 1.5.4a and earlier allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: due to lack of details from the researcher, it is not clear whether this overlaps CVE-2004-2207.  Assigned (20060511)  None (candidate not yet proposed)    View

Page 20409 of 20943, showing 5 records out of 104715 total, starting on record 102041, ending on 102045

Actions