CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
22782 | CVE-2006-6678 | Candidate | The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename. | Assigned (20061220) | None (candidate not yet proposed) | View | |
88318 | CVE-2016-1499 | Candidate | ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php. | Assigned (20160106) | None (candidate not yet proposed) | View | |
23038 | CVE-2006-6934 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Portix-PHP 0.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) titre or (2) auteur field in a forum post. | Assigned (20070116) | None (candidate not yet proposed) | View | |
88574 | CVE-2016-1755 | Candidate | The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754. | Assigned (20160113) | None (candidate not yet proposed) | View | |
23294 | CVE-2006-7190 | Candidate | Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic instead of doubbc. | Assigned (20070402) | None (candidate not yet proposed) | View |
Page 20784 of 20943, showing 5 records out of 104715 total, starting on record 103916, ending on 103920