CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26862  CVE-2007-3505  Candidate  Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.  Assigned (20070702)  None (candidate not yet proposed)    View
92398  CVE-2016-5579  Candidate  Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 through 8.5.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-5558, CVE-2016-5574, CVE-2016-5577, CVE-2016-5578, and CVE-2016-5588.  Assigned (20160616)  None (candidate not yet proposed)    View
27118  CVE-2007-3761  Candidate  Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1 allows remote attackers to inject arbitrary web script or HTML by causing Javascript events to be applied to a frame in another domain.  Assigned (20070712)  None (candidate not yet proposed)    View
92654  CVE-2016-5834  Candidate  Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.  Assigned (20160623)  None (candidate not yet proposed)    View
27374  CVE-2007-4017  Candidate  Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators.  Assigned (20070725)  None (candidate not yet proposed)    View

Page 19557 of 20943, showing 5 records out of 104715 total, starting on record 97781, ending on 97785

Actions