CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18954  CVE-2006-2850  Candidate  Cross-site scripting (XSS) vulnerability in recentchanges.php in PHP Labware LabWiki 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the help parameter.  Assigned (20060605)  None (candidate not yet proposed)    View
84490  CVE-2015-7213  Candidate  Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.  Assigned (20150916)  None (candidate not yet proposed)    View
19210  CVE-2006-3106  Candidate  Cross-site scripting (XSS) vulnerability in index.php in phpMyDesktop|Arcade 1.0 allows remote attackers to inject arbitrary web script or HTML via the subsite parameter in the subsite todo.  Assigned (20060620)  None (candidate not yet proposed)    View
84746  CVE-2015-7469  Candidate  Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.  Assigned (20150929)  None (candidate not yet proposed)    View
19466  CVE-2006-3362  Candidate  Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.  Assigned (20060706)  None (candidate not yet proposed)    View

Page 835 of 20943, showing 5 records out of 104715 total, starting on record 4171, ending on 4175

Actions