CVE List

Id CVE No. Status Description Phase Votes Comments Actions
86521  CVE-2016-0225  Candidate  IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.  Assigned (20151208)  None (candidate not yet proposed)    View
21241  CVE-2006-5137  Candidate  Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doedittheme.php, which is injected into includes/theme.inc.php; (2) inject PHP code via a config[] array parameter to admin/doeditconfig.php, and then execute the code via includes/config.inc.php; and inject a reference to PHP code via a URL in the config[path] parameter, and then execute the code via (3) dorateuser.php, (4) calendar.php, and unspecified other scripts.  Assigned (20061002)  None (candidate not yet proposed)    View
86777  CVE-2016-0481  Candidate  Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0482, CVE-2016-0485, and CVE-2016-0486. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scheduleReportName parameter.  Assigned (20151209)  None (candidate not yet proposed)    View
21497  CVE-2006-5393  Candidate  Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user"s SSL VPN session.  Assigned (20061018)  None (candidate not yet proposed)    View
87033  CVE-2016-0737  Candidate  OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.  Assigned (20151216)  None (candidate not yet proposed)    View

Page 20414 of 20943, showing 5 records out of 104715 total, starting on record 102066, ending on 102070

Actions