CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23300  CVE-2006-7196  Candidate  Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.  Assigned (20070422)  None (candidate not yet proposed)    View
88836  CVE-2016-2017  Candidate  HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.  Assigned (20160122)  None (candidate not yet proposed)    View
23556  CVE-2007-0199  Candidate  The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."  Assigned (20070110)  None (candidate not yet proposed)    View
89092  CVE-2016-2273  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160209)  None (candidate not yet proposed)    View
23812  CVE-2007-0455  Candidate  Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.  Assigned (20070123)  None (candidate not yet proposed)    View

Page 359 of 20943, showing 5 records out of 104715 total, starting on record 1791, ending on 1795

Actions