CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15880  CVE-2005-4676  Candidate  Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.  Assigned (20060131)  None (candidate not yet proposed)    View
81416  CVE-2015-4139  Candidate  Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the s4w-more parameter to wp-admin/options-general.php.  Assigned (20150531)  None (candidate not yet proposed)    View
16136  CVE-2006-0032  Candidate  Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.  Assigned (20051130)  None (candidate not yet proposed)    View
81672  CVE-2015-4395  Candidate  The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user for a password when registering" option is enabled, which allows remote authenticated users with certain permissions to obtain sensitive information by leveraging access to the database.  Assigned (20150605)  None (candidate not yet proposed)    View
16392  CVE-2006-0288  Candidate  Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02.  Assigned (20060118)  None (candidate not yet proposed)    View

Page 663 of 20943, showing 5 records out of 104715 total, starting on record 3311, ending on 3315

Actions