CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18412  CVE-2006-2308  Candidate  Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user"s email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY or (6) APPEND commands.  Assigned (20060511)  None (candidate not yet proposed)    View
83948  CVE-2015-6671  Candidate  Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.  Assigned (20150825)  None (candidate not yet proposed)    View
18668  CVE-2006-2564  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlstraSoft E-Friends allow remote attackers to inject arbitrary web script or HTML by (1) posting a blog, (2) posting a listing, (3) posting an event, (4) adding comments, or (5) sending a message.  Assigned (20060524)  None (candidate not yet proposed)    View
84204  CVE-2015-6927  Candidate  vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel.  Assigned (20150914)  None (candidate not yet proposed)    View
18924  CVE-2006-2820  Candidate  Cross-site scripting (XSS) vulnerability in HotWebScripts.com Weblog Oggi 1.0 allows remote attackers to inject arbitrary web script or HTML via a comment, possibly involving a javascript URI in the SRC attribute of an IMG element.  Assigned (20060605)  None (candidate not yet proposed)    View

Page 19379 of 20943, showing 5 records out of 104715 total, starting on record 96891, ending on 96895

Actions