CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
17394 | CVE-2006-1290 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) username, and (4) unspecified other parameters in (a) authuser.php; and the (5) username and (6) unspecified other parameters in (b) userstatistics.php. | Assigned (20060319) | None (candidate not yet proposed) | View | |
82930 | CVE-2015-5653 | Candidate | Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet. | Assigned (20150724) | None (candidate not yet proposed) | View | |
17650 | CVE-2006-1546 | Candidate | Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a "org.apache.struts.taglib.html.Constants.CANCEL" parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check. | Assigned (20060330) | None (candidate not yet proposed) | View | |
83186 | CVE-2015-5909 | Candidate | IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery. | Assigned (20150806) | None (candidate not yet proposed) | View | |
17906 | CVE-2006-1802 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter. | Assigned (20060417) | None (candidate not yet proposed) | View |
Page 18727 of 20943, showing 5 records out of 104715 total, starting on record 93631, ending on 93635