NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59613 | CVE-2006-0884 | The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail. | 2 | 9.3 | High | 2016-12-20 | 2011-05-25 | View | |
| 59869 | CVE-2006-1147 | The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenticated) to cause a denial of service (application crash) via a long skin, weapon, or model name. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 60125 | CVE-2006-1416 | Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 60381 | CVE-2006-1676 | SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP. | 2 | 6.4 | Medium | 2016-12-20 | 2011-08-05 | View | |
| 60637 | CVE-2006-1932 | Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View |
Page 15607 of 17672, showing 5 records out of 88360 total, starting on record 78031, ending on 78035