CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88549  CVE-2016-1730  Candidate  WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.  Assigned (20160113)  None (candidate not yet proposed)    View
75136  CVE-2014-7835  Candidate  webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.  Assigned (20141003)  None (candidate not yet proposed)    View
57645  CVE-2012-4402  Candidate  webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.  Assigned (20120821)  None (candidate not yet proposed)    View
80256  CVE-2015-2979  Candidate  Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.  Assigned (20150407)  None (candidate not yet proposed)    View
80254  CVE-2015-2977  Candidate  Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors.  Assigned (20150407)  None (candidate not yet proposed)    View

Page 235 of 20943, showing 5 records out of 104715 total, starting on record 1171, ending on 1175

Actions