NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
24193  CVE-2015-2011  The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.    High  2017-01-19  2015-10-05  View
67704  CVE-2005-1992  The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands.    7.5  High  2017-01-03  2013-08-21  View
11956  CVE-2010-0397  The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.    Medium  2017-01-18  2010-12-10  View
36591  CVE-2013-0235  The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.    6.4  Medium  2017-01-18  2013-07-08  View
24053  CVE-2015-1819  The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.    Medium  2017-01-19  2016-12-21  View

Page 2589 of 17672, showing 5 records out of 88360 total, starting on record 12941, ending on 12945

Actions