CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17673  CVE-2006-1569  Candidate  Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters to (a) login.php or (b) register.php; or (3) u parameter to (c) profile.php.  Assigned (20060331)  None (candidate not yet proposed)    View
83209  CVE-2015-5932  Candidate  The kernel in Apple OS X before 10.11.1 allows local users to gain privileges by leveraging an unspecified "type confusion" during Mach task processing.  Assigned (20150806)  None (candidate not yet proposed)    View
17929  CVE-2006-1825  Candidate  Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.  Assigned (20060417)  None (candidate not yet proposed)    View
83465  CVE-2015-6188  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150814)  None (candidate not yet proposed)    View
18185  CVE-2006-2081  Candidate  Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADATA function in the DBMS_EXPORT_EXTENSION package. NOTE: this issue was originally linked to DB05 (CVE-2006-1870), but a reliable third party has claimed that it is not the same issue. Based on details of the problem, the primary issue appears to be insecure privileges that facilitate the introduction of SQL in a way that is not releated to special characters, so this is not "SQL injection" per se.  Assigned (20060427)  None (candidate not yet proposed)    View

Page 755 of 20943, showing 5 records out of 104715 total, starting on record 3771, ending on 3775

Actions