CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25612  CVE-2007-2255  Candidate  Multiple PHP remote file inclusion vulnerabilities in Download-Engine 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) eng_dir parameter to addmember.php, (2) lang_path parameter to admin/enginelib/class.phpmailer.php, and the (3) spaw_root parameter to admin/includes/spaw/dialogs/colorpicker.php, different vectors than CVE-2006-5291 and CVE-2006-5459. NOTE: vector 3 might be an issue in SPAW.  Assigned (20070425)  None (candidate not yet proposed)    View
91148  CVE-2016-4329  Candidate  A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism.  Assigned (20160427)  None (candidate not yet proposed)    View
25868  CVE-2007-2511  Candidate  Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.  Assigned (20070507)  None (candidate not yet proposed)    View
91404  CVE-2016-4585  Candidate  Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to inject arbitrary web script or HTML via an HTTP response specifying redirection that is mishandled by Safari.  Assigned (20160511)  None (candidate not yet proposed)    View
26124  CVE-2007-2767  Candidate  Unspecified vulnerability in BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 allows remote attackers to list filesystem contents and obtain sensitive information via unknown vectors.  Assigned (20070521)  None (candidate not yet proposed)    View

Page 1007 of 20943, showing 5 records out of 104715 total, starting on record 5031, ending on 5035

Actions