NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63810  CVE-2006-5204  Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.    2.1  Low  2016-12-20  2011-03-07  View
64066  CVE-2006-5465  Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.    7.5  High  2016-12-20  2011-03-07  View
64322  CVE-2006-5747  Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.    7.5  High  2016-12-20  2011-03-07  View
64578  CVE-2006-6017  WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.    Medium  2016-12-20  2008-09-05  View
64834  CVE-2006-6273  sp_index.php in Simple PHP Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid dir parameter, which reveals the path in an error message.    7.5  High  2016-12-20  2008-09-05  View

Page 381 of 17672, showing 5 records out of 88360 total, starting on record 1901, ending on 1905

Actions