NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
65059  CVE-2006-6514  Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application"s root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:folder2 when the root directory is C:folder.    3.5  Low  2016-12-20  2011-03-07  View
10532  CVE-2011-3978  Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page.    3.5  Low  2017-01-07  2012-02-13  View
14884  CVE-2010-3505  Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders, Files & Attachments, a different vulnerability than CVE-2010-4429.    3.5  Low  2017-01-18  2011-01-26  View
19748  CVE-2016-4028  An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users credentials. The OX Guard API acts as a padding oracle by responding with different error codes depending on whether the provided token matches the encryption padding. In combination with AES-CBC, this allows attackers to guess the correct padding. Attackers may run brute-forcing attacks on the content of the guest authentication token and discover user credentials. For a practical attack vector, the guest users needs to have logged in, the content of the guest user"s "OxReaderID" cookie and the value of the "auth" parameter needs to be known to the attacker.    3.5  Low  2017-01-19  2016-12-16  View
85796  CVE-2017-0890  Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.    3.5  Low  2017-05-27  2017-05-17  View

Page 2572 of 17672, showing 5 records out of 88360 total, starting on record 12856, ending on 12860

Actions