CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102149 | CVE-2017-5329 | Candidate | Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation. | Assigned (20170109) | None (candidate not yet proposed) | View | |
36869 | CVE-2008-6752 | Candidate | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator"s password and gain privileges via a direct request with modified newpass1 and newpass2 parameters in a Change operation. | Assigned (20090424) | None (candidate not yet proposed) | View | |
102405 | CVE-2017-5585 | Candidate | OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL commands via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2520. | Assigned (20170125) | None (candidate not yet proposed) | View | |
37125 | CVE-2008-7008 | Candidate | HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db. | Assigned (20090818) | None (candidate not yet proposed) | View | |
102661 | CVE-2017-5841 | Candidate | The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags. | Assigned (20170201) | None (candidate not yet proposed) | View |
Page 1066 of 20943, showing 5 records out of 104715 total, starting on record 5326, ending on 5330