CVE List

Id CVE No. Status Description Phase Votes Comments Actions
16127  CVE-2006-0023  Candidate  Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.  Assigned (20051130)  None (candidate not yet proposed)    View
81663  CVE-2015-4386  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes.  Assigned (20150605)  None (candidate not yet proposed)    View
16383  CVE-2006-0279  Candidate  Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component.  Assigned (20060118)  None (candidate not yet proposed)    View
81919  CVE-2015-4642  Candidate  The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.  Assigned (20150618)  None (candidate not yet proposed)    View
16639  CVE-2006-0535  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20060203)  None (candidate not yet proposed)    View

Page 20887 of 20943, showing 5 records out of 104715 total, starting on record 104431, ending on 104435

Actions