CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81412  CVE-2015-4135  Candidate  Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter.  Assigned (20150528)  None (candidate not yet proposed)    View
16132  CVE-2006-0028  Candidate  Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.  Assigned (20051130)  None (candidate not yet proposed)    View
81668  CVE-2015-4391  Candidate  Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of users for requests that delete reports via unspecified vectors.  Assigned (20150605)  None (candidate not yet proposed)    View
16388  CVE-2006-0284  Candidate  Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component.  Assigned (20060118)  None (candidate not yet proposed)    View
81924  CVE-2015-4647  Candidate  Multiple stack-based buffer overflows in Ipropsapi in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allow remote attackers to execute arbitrary code via a long string in the (1) FilePassword property or to the (2) GetStringInfo method.  Assigned (20150618)  None (candidate not yet proposed)    View

Page 343 of 20943, showing 5 records out of 104715 total, starting on record 1711, ending on 1715

Actions