CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30732  CVE-2008-0615  Candidate  Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.  Assigned (20080205)  None (candidate not yet proposed)    View
96268  CVE-2016-9448  Candidate  The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297.  Assigned (20161118)  None (candidate not yet proposed)    View
30988  CVE-2008-0871  Candidate  Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.  Assigned (20080221)  None (candidate not yet proposed)    View
96524  CVE-2016-9704  Candidate  IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  Assigned (20161201)  None (candidate not yet proposed)    View
31244  CVE-2008-1127  Candidate  Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name, which is triggered when the game character is killed.  Assigned (20080303)  None (candidate not yet proposed)    View

Page 1006 of 20943, showing 5 records out of 104715 total, starting on record 5026, ending on 5030

Actions