CVE List

Id CVE No. Status Description Phase Votes Comments Actions
19706  CVE-2006-3602  Candidate  Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the language parameter in the advanced theme.  Assigned (20060714)  None (candidate not yet proposed)    View
85242  CVE-2015-7965  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20151023)  None (candidate not yet proposed)    View
19962  CVE-2006-3858  Candidate  IBM Informix Dynamic Server (IDS) before 9.40.xC8 and 10.00 before 10.00.xC4 stores passwords in plaintext in shared memory, which allows local users to obtain passwords by reading the memory (product defects 171893, 171894, 173772).  Assigned (20060726)  None (candidate not yet proposed)    View
85498  CVE-2015-8221  Candidate  Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.  Assigned (20151117)  None (candidate not yet proposed)    View
20218  CVE-2006-4114  Candidate  SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.  Assigned (20060814)  None (candidate not yet proposed)    View

Page 20471 of 20943, showing 5 records out of 104715 total, starting on record 102351, ending on 102355

Actions