CVE List

Id CVE No. Status Description Phase Votes Comments Actions
82674  CVE-2015-5397  Candidate  Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.  Assigned (20150706)  None (candidate not yet proposed)    View
17394  CVE-2006-1290  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) username, and (4) unspecified other parameters in (a) authuser.php; and the (5) username and (6) unspecified other parameters in (b) userstatistics.php.  Assigned (20060319)  None (candidate not yet proposed)    View
82930  CVE-2015-5653  Candidate  Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.  Assigned (20150724)  None (candidate not yet proposed)    View
17650  CVE-2006-1546  Candidate  Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a "org.apache.struts.taglib.html.Constants.CANCEL" parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.  Assigned (20060330)  None (candidate not yet proposed)    View
83186  CVE-2015-5909  Candidate  IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.  Assigned (20150806)  None (candidate not yet proposed)    View

Page 19244 of 20943, showing 5 records out of 104715 total, starting on record 96216, ending on 96220

Actions