CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
84464 | CVE-2015-7187 | Candidate | The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension. | Assigned (20150916) | None (candidate not yet proposed) | View | |
19184 | CVE-2006-3080 | Candidate | Cross-site scripting (XSS) vulnerability in viewposts.cfm in aXentForum II and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter. | Assigned (20060619) | None (candidate not yet proposed) | View | |
84720 | CVE-2015-7443 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150929) | None (candidate not yet proposed) | View | |
19440 | CVE-2006-3336 | Candidate | TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory. | Assigned (20060702) | None (candidate not yet proposed) | View | |
84976 | CVE-2015-7699 | Candidate | The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore." | Assigned (20151004) | None (candidate not yet proposed) | View |
Page 19690 of 20943, showing 5 records out of 104715 total, starting on record 98446, ending on 98450