CVE List

Id CVE No. Status Description Phase Votes Comments Actions
82676  CVE-2015-5399  Candidate  Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.  Assigned (20150706)  None (candidate not yet proposed)    View
17396  CVE-2006-1292  Candidate  Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.  Assigned (20060319)  None (candidate not yet proposed)    View
82932  CVE-2015-5655  Candidate  The Adways Party Track SDK before 1.6.6 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20150724)  None (candidate not yet proposed)    View
17652  CVE-2006-1548  Candidate  Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.  Assigned (20060330)  None (candidate not yet proposed)    View
83188  CVE-2015-5911  Candidate  Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.  Assigned (20150806)  None (candidate not yet proposed)    View

Page 19403 of 20943, showing 5 records out of 104715 total, starting on record 97011, ending on 97015

Actions