CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
88549 | CVE-2016-1730 | Candidate | WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal. | Assigned (20160113) | None (candidate not yet proposed) | View | |
75136 | CVE-2014-7835 | Candidate | webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area. | Assigned (20141003) | None (candidate not yet proposed) | View | |
57645 | CVE-2012-4402 | Candidate | webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service. | Assigned (20120821) | None (candidate not yet proposed) | View | |
80256 | CVE-2015-2979 | Candidate | Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors. | Assigned (20150407) | None (candidate not yet proposed) | View | |
80254 | CVE-2015-2977 | Candidate | Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors. | Assigned (20150407) | None (candidate not yet proposed) | View |
Page 235 of 20943, showing 5 records out of 104715 total, starting on record 1171, ending on 1175