CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21763  CVE-2006-5659  Candidate  PAM_extern before 0.2 sends a password as a command line argument, which allows local users to obtain the password by listing the command line arguments, such as ps. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20061102)  None (candidate not yet proposed)    View
87299  CVE-2016-1000001  Candidate  flask-oidc version 0.1.2 and earlier is vulnerable to an open redirect  Assigned (20160519)  None (candidate not yet proposed)    View
22019  CVE-2006-5915  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7) search_order parameter.  Assigned (20061115)  None (candidate not yet proposed)    View
87555  CVE-2016-10059  Candidate  Buffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows remote attackers to cause a denial of service (application crash) or have unspecified other impact via a crafted TIFF file.  Assigned (20161226)  None (candidate not yet proposed)    View
22275  CVE-2006-6171  Candidate  ** DISPUTED ** ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability.  Assigned (20061130)  None (candidate not yet proposed)    View

Page 272 of 20943, showing 5 records out of 104715 total, starting on record 1356, ending on 1360

Actions