CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
82941 | CVE-2015-5664 | Candidate | Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150724) | None (candidate not yet proposed) | View | |
17661 | CVE-2006-1557 | Candidate | Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php. | Assigned (20060331) | None (candidate not yet proposed) | View | |
83197 | CVE-2015-5920 | Candidate | The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors. | Assigned (20150806) | None (candidate not yet proposed) | View | |
17917 | CVE-2006-1813 | Candidate | Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter. | Assigned (20060417) | None (candidate not yet proposed) | View | |
83453 | CVE-2015-6176 | Candidate | Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability." | Assigned (20150814) | None (candidate not yet proposed) | View |
Page 20730 of 20943, showing 5 records out of 104715 total, starting on record 103646, ending on 103650