CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
86250 | CVE-2015-8973 | Candidate | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password. | Assigned (20161117) | None (candidate not yet proposed) | View | |
4451 | CVE-2002-0057 | Entry | XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source. | View | |||
35057 | CVE-2008-4940 | Candidate | xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file. | Assigned (20081105) | None (candidate not yet proposed) | View | |
36176 | CVE-2008-6059 | Candidate | xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. | Assigned (20090204) | None (candidate not yet proposed) | View | |
62108 | CVE-2013-2161 | Candidate | XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name. | Assigned (20130219) | None (candidate not yet proposed) | View |
Page 69 of 20943, showing 5 records out of 104715 total, starting on record 341, ending on 345