CVE List

Id CVE No. Status Description Phase Votes Comments Actions
84491  CVE-2015-7214  Candidate  Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.  Assigned (20150916)  None (candidate not yet proposed)    View
19211  CVE-2006-3107  Candidate  Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) admin/modules/news/news_class.php and (b) admin/modules/content/content_class.php, and (2) GLOBALS[where_cms] to (c) admin/modules/block_media/util.media.php. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576, but the vectors are different.  Assigned (20060620)  None (candidate not yet proposed)    View
84747  CVE-2015-7470  Candidate  Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.  Assigned (20150929)  None (candidate not yet proposed)    View
19467  CVE-2006-3363  Candidate  PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.  Assigned (20060706)  None (candidate not yet proposed)    View
85003  CVE-2015-7726  Candidate  Cross-site scripting (XSS) vulnerability in role deletion in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allows remote authenticated users to inject arbitrary web script or HTML via the role name, aka SAP Security Note 2153898.  Assigned (20151006)  None (candidate not yet proposed)    View

Page 906 of 20943, showing 5 records out of 104715 total, starting on record 4526, ending on 4530

Actions