NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59357 | CVE-2006-0626 | SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59613 | CVE-2006-0884 | The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail. | 2 | 9.3 | High | 2016-12-20 | 2011-05-25 | View | |
59869 | CVE-2006-1147 | The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenticated) to cause a denial of service (application crash) via a long skin, weapon, or model name. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
60125 | CVE-2006-1416 | Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60381 | CVE-2006-1676 | SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP. | 2 | 6.4 | Medium | 2016-12-20 | 2011-08-05 | View |
Page 17469 of 17672, showing 5 records out of 88360 total, starting on record 87341, ending on 87345