CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26618  CVE-2007-3261  Candidate  Cross-site scripting (XSS) vulnerability in widgets/widget_search.php in dKret before 2.6 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).  Assigned (20070619)  None (candidate not yet proposed)    View
92154  CVE-2016-5335  Candidate  VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.  Assigned (20160607)  None (candidate not yet proposed)    View
26874  CVE-2007-3517  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.  Assigned (20070703)  None (candidate not yet proposed)    View
92410  CVE-2016-5591  Candidate  Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5593.  Assigned (20160616)  None (candidate not yet proposed)    View
27130  CVE-2007-3773  Candidate  Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators.  Assigned (20070715)  None (candidate not yet proposed)    View

Page 20505 of 20943, showing 5 records out of 104715 total, starting on record 102521, ending on 102525

Actions