CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
81412 | CVE-2015-4135 | Candidate | Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | Assigned (20150528) | None (candidate not yet proposed) | View | |
16132 | CVE-2006-0028 | Candidate | Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers. | Assigned (20051130) | None (candidate not yet proposed) | View | |
81668 | CVE-2015-4391 | Candidate | Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of users for requests that delete reports via unspecified vectors. | Assigned (20150605) | None (candidate not yet proposed) | View | |
16388 | CVE-2006-0284 | Candidate | Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component. | Assigned (20060118) | None (candidate not yet proposed) | View | |
81924 | CVE-2015-4647 | Candidate | Multiple stack-based buffer overflows in Ipropsapi in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allow remote attackers to execute arbitrary code via a long string in the (1) FilePassword property or to the (2) GetStringInfo method. | Assigned (20150618) | None (candidate not yet proposed) | View |
Page 343 of 20943, showing 5 records out of 104715 total, starting on record 1711, ending on 1715