CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
81174 | CVE-2015-3897 | Candidate | Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource. | Assigned (20150512) | None (candidate not yet proposed) | View | |
15894 | CVE-2005-4690 | Candidate | Six Apart Movable Type 3.16 allows local users with blog-creation privileges to create or overwrite arbitrary files of certain types (such as HTML and image files) by selecting an arbitrary directory as a blog"s top-level directory. NOTE: this issue can be used in conjunction with CVE-2005-3102 to create or overwrite arbitrary files of all types. | Assigned (20060131) | None (candidate not yet proposed) | View | |
81430 | CVE-2015-4153 | Candidate | Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php. | Assigned (20150601) | None (candidate not yet proposed) | View | |
16150 | CVE-2006-0046 | Candidate | squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions. | Assigned (20051228) | None (candidate not yet proposed) | View | |
81686 | CVE-2015-4409 | Candidate | Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the SDK issue. | Assigned (20150606) | None (candidate not yet proposed) | View |
Page 1773 of 20943, showing 5 records out of 104715 total, starting on record 8861, ending on 8865