CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21003  CVE-2006-4899  Candidate  The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a """ (single quote) in the PIProfile function, which leaks the path in an error message.  Assigned (20060920)  None (candidate not yet proposed)    View
86539  CVE-2016-0243  Candidate  Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0244.  Assigned (20151208)  None (candidate not yet proposed)    View
21259  CVE-2006-5155  Candidate  PHP remote file inclusion vulnerability in core/pdf.php in VideoDB 2.2.1 and earlier allows remote attackers to execute arbitrary PHP code via the config[pdf_module] parameter.  Assigned (20061003)  None (candidate not yet proposed)    View
86795  CVE-2016-0499  Candidate  Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4794.  Assigned (20151209)  None (candidate not yet proposed)    View
21515  CVE-2006-5411  Candidate  Unrestricted file upload vulnerability in upload.php for Free Web Publishing System (FreeWPS), possibly 2.11 and earlier, allows remote attackers to upload and execute arbitrary PHP programs.  Assigned (20061019)  None (candidate not yet proposed)    View

Page 909 of 20943, showing 5 records out of 104715 total, starting on record 4541, ending on 4545

Actions