CVE List

Id CVE No. Status Description Phase Votes Comments Actions
82941  CVE-2015-5664  Candidate  Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150724)  None (candidate not yet proposed)    View
17661  CVE-2006-1557  Candidate  Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.  Assigned (20060331)  None (candidate not yet proposed)    View
83197  CVE-2015-5920  Candidate  The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.  Assigned (20150806)  None (candidate not yet proposed)    View
17917  CVE-2006-1813  Candidate  Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.  Assigned (20060417)  None (candidate not yet proposed)    View
83453  CVE-2015-6176  Candidate  Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."  Assigned (20150814)  None (candidate not yet proposed)    View

Page 20730 of 20943, showing 5 records out of 104715 total, starting on record 103646, ending on 103650

Actions