CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81664  CVE-2015-4387  Candidate  Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source.  Assigned (20150605)  None (candidate not yet proposed)    View
16384  CVE-2006-0280  Candidate  Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.  Assigned (20060118)  None (candidate not yet proposed)    View
81920  CVE-2015-4643  Candidate  Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.  Assigned (20150618)  None (candidate not yet proposed)    View
16640  CVE-2006-0536  Candidate  Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. NOTE: some sources say that the affected parameter is "date," but the demonstration URL shows that it is "sort".  Assigned (20060203)  None (candidate not yet proposed)    View
82176  CVE-2015-4899  Candidate  Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality via unknown vectors related to Security.  Assigned (20150624)  None (candidate not yet proposed)    View

Page 25 of 20943, showing 5 records out of 104715 total, starting on record 121, ending on 125

Actions