CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22025  CVE-2006-5921  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, and (3) Comment fields. NOTE: this issue may overlap CVE-2006-5195.  Assigned (20061115)  None (candidate not yet proposed)    View
87561  CVE-2016-10064  Candidate  Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.  Assigned (20161226)  None (candidate not yet proposed)    View
22281  CVE-2006-6177  Candidate  SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and " (apostrophe) (%2500%2527).  Assigned (20061130)  None (candidate not yet proposed)    View
87817  CVE-2016-10297  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170328)  None (candidate not yet proposed)    View
22537  CVE-2006-6433  Candidate  Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 does not record accurate timestamps, which makes it easier for remote attackers to avoid detection when an audit tries to rely on these timestamps.  Assigned (20061209)  None (candidate not yet proposed)    View

Page 752 of 20943, showing 5 records out of 104715 total, starting on record 3756, ending on 3760

Actions