CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
82676 | CVE-2015-5399 | Candidate | Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment. | Assigned (20150706) | None (candidate not yet proposed) | View | |
17396 | CVE-2006-1292 | Candidate | Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php. | Assigned (20060319) | None (candidate not yet proposed) | View | |
82932 | CVE-2015-5655 | Candidate | The Adways Party Track SDK before 1.6.6 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20150724) | None (candidate not yet proposed) | View | |
17652 | CVE-2006-1548 | Candidate | Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message. | Assigned (20060330) | None (candidate not yet proposed) | View | |
83188 | CVE-2015-5911 | Candidate | Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document. | Assigned (20150806) | None (candidate not yet proposed) | View |
Page 19403 of 20943, showing 5 records out of 104715 total, starting on record 97011, ending on 97015