CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22278  CVE-2006-6174  Candidate  Cross-site scripting (XSS) vulnerability in tDiary before 2.0.3 and 2.1.x before 2.1.4.20061126 allows remote attackers to inject arbitrary web script or HTML via the conf parameter in (1) tdiary.rb and (2) skel/conf.rhtml.  Assigned (20061130)  None (candidate not yet proposed)    View
87814  CVE-2016-10294  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170328)  None (candidate not yet proposed)    View
22534  CVE-2006-6430  Candidate  Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic.  Assigned (20061209)  None (candidate not yet proposed)    View
88070  CVE-2016-1251  Candidate  There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.  Assigned (20151227)  None (candidate not yet proposed)    View
22790  CVE-2006-6686  Candidate  PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.  Assigned (20061221)  None (candidate not yet proposed)    View

Page 518 of 20943, showing 5 records out of 104715 total, starting on record 2586, ending on 2590

Actions