CVE List

Id CVE No. Status Description Phase Votes Comments Actions
89349  CVE-2016-2530  Candidate  The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 mishandles the case of an unrecognized TLV type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet, a different vulnerability than CVE-2016-2531.  Assigned (20160220)  None (candidate not yet proposed)    View
24069  CVE-2007-0712  Candidate  Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.  Assigned (20070205)  None (candidate not yet proposed)    View
89605  CVE-2016-2786  Candidate  The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate.  Assigned (20160229)  None (candidate not yet proposed)    View
24325  CVE-2007-0968  Candidate  Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.  Assigned (20070215)  None (candidate not yet proposed)    View
89861  CVE-2016-3042  Candidate  Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.  Assigned (20160309)  None (candidate not yet proposed)    View

Page 1046 of 20943, showing 5 records out of 104715 total, starting on record 5226, ending on 5230

Actions