CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17395  CVE-2006-1291  Candidate  publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with a filename containing a .php extension and a trailing null character.  Assigned (20060319)  None (candidate not yet proposed)    View
82931  CVE-2015-5654  Candidate  Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150724)  None (candidate not yet proposed)    View
17651  CVE-2006-1547  Candidate  ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.  Assigned (20060330)  None (candidate not yet proposed)    View
83187  CVE-2015-5910  Candidate  IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network.  Assigned (20150806)  None (candidate not yet proposed)    View
17907  CVE-2006-1803  Candidate  Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.  Assigned (20060417)  None (candidate not yet proposed)    View

Page 18804 of 20943, showing 5 records out of 104715 total, starting on record 94016, ending on 94020

Actions