NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 24193 | CVE-2015-2011 | The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors. | 2 | 9 | High | 2017-01-19 | 2015-10-05 | View | |
| 67704 | CVE-2005-1992 | The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands. | 2 | 7.5 | High | 2017-01-03 | 2013-08-21 | View | |
| 11956 | CVE-2010-0397 | The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument. | 2 | 5 | Medium | 2017-01-18 | 2010-12-10 | View | |
| 36591 | CVE-2013-0235 | The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue. | 2 | 6.4 | Medium | 2017-01-18 | 2013-07-08 | View | |
| 24053 | CVE-2015-1819 | The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 2589 of 17672, showing 5 records out of 88360 total, starting on record 12941, ending on 12945