CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15867  CVE-2005-4663  Candidate  Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  Assigned (20060116)  None (candidate not yet proposed)    View
81403  CVE-2015-4126  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150528)  None (candidate not yet proposed)    View
16123  CVE-2006-0019  Candidate  Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.  Assigned (20051220)  None (candidate not yet proposed)    View
81659  CVE-2015-4382  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) create, (2) delete, or (3) alter invoices via unspecified vectors.  Assigned (20150605)  None (candidate not yet proposed)    View
16379  CVE-2006-0275  Candidate  Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04. NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.  Assigned (20060118)  None (candidate not yet proposed)    View

Page 20542 of 20943, showing 5 records out of 104715 total, starting on record 102706, ending on 102710

Actions