CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25861  CVE-2007-2504  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in user/turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[tcore] parameter. NOTE: this vulnerability is disputed by CVE and a reliable third party because a direct request to user/turbulence.php triggers a fatal error before inclusion.  Assigned (20070503)  None (candidate not yet proposed)    View
91397  CVE-2016-4578  Candidate  sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.  Assigned (20160511)  None (candidate not yet proposed)    View
26117  CVE-2007-2760  Candidate  The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.  Assigned (20070518)  None (candidate not yet proposed)    View
91653  CVE-2016-4834  Candidate  modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.  Assigned (20160517)  None (candidate not yet proposed)    View
26373  CVE-2007-3016  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20070604)  None (candidate not yet proposed)    View

Page 1049 of 20943, showing 5 records out of 104715 total, starting on record 5241, ending on 5245

Actions