CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
82674 | CVE-2015-5397 | Candidate | Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors. | Assigned (20150706) | None (candidate not yet proposed) | View | |
17394 | CVE-2006-1290 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) username, and (4) unspecified other parameters in (a) authuser.php; and the (5) username and (6) unspecified other parameters in (b) userstatistics.php. | Assigned (20060319) | None (candidate not yet proposed) | View | |
82930 | CVE-2015-5653 | Candidate | Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet. | Assigned (20150724) | None (candidate not yet proposed) | View | |
17650 | CVE-2006-1546 | Candidate | Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a "org.apache.struts.taglib.html.Constants.CANCEL" parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check. | Assigned (20060330) | None (candidate not yet proposed) | View | |
83186 | CVE-2015-5909 | Candidate | IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery. | Assigned (20150806) | None (candidate not yet proposed) | View |
Page 19244 of 20943, showing 5 records out of 104715 total, starting on record 96216, ending on 96220