CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90629  CVE-2016-3810  Candidate  The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28175522 and MediaTek internal bug ALPS02694389.  Assigned (20160330)  None (candidate not yet proposed)    View
25349  CVE-2007-1992  Candidate  Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/.  Assigned (20070411)  None (candidate not yet proposed)    View
90885  CVE-2016-4066  Candidate  Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrators for requests that change the password via unspecified vectors.  Assigned (20160422)  None (candidate not yet proposed)    View
25605  CVE-2007-2248  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.  Assigned (20070425)  None (candidate not yet proposed)    View
91141  CVE-2016-4322  Candidate  BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.  Assigned (20160427)  None (candidate not yet proposed)    View

Page 1048 of 20943, showing 5 records out of 104715 total, starting on record 5236, ending on 5240

Actions