CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22782  CVE-2006-6678  Candidate  The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.  Assigned (20061220)  None (candidate not yet proposed)    View
88318  CVE-2016-1499  Candidate  ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.  Assigned (20160106)  None (candidate not yet proposed)    View
23038  CVE-2006-6934  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Portix-PHP 0.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) titre or (2) auteur field in a forum post.  Assigned (20070116)  None (candidate not yet proposed)    View
88574  CVE-2016-1755  Candidate  The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.  Assigned (20160113)  None (candidate not yet proposed)    View
23294  CVE-2006-7190  Candidate  Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic instead of doubbc.  Assigned (20070402)  None (candidate not yet proposed)    View

Page 20784 of 20943, showing 5 records out of 104715 total, starting on record 103916, ending on 103920

Actions