CVE List

Id CVE No. Status Description Phase Votes Comments Actions
84464  CVE-2015-7187  Candidate  The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.  Assigned (20150916)  None (candidate not yet proposed)    View
19184  CVE-2006-3080  Candidate  Cross-site scripting (XSS) vulnerability in viewposts.cfm in aXentForum II and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter.  Assigned (20060619)  None (candidate not yet proposed)    View
84720  CVE-2015-7443  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150929)  None (candidate not yet proposed)    View
19440  CVE-2006-3336  Candidate  TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory.  Assigned (20060702)  None (candidate not yet proposed)    View
84976  CVE-2015-7699  Candidate  The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."  Assigned (20151004)  None (candidate not yet proposed)    View

Page 19690 of 20943, showing 5 records out of 104715 total, starting on record 98446, ending on 98450

Actions