CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90893  CVE-2016-4074  Candidate  The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file.  Assigned (20160424)  None (candidate not yet proposed)    View
25613  CVE-2007-2256  Candidate  Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter.  Assigned (20070425)  None (candidate not yet proposed)    View
91149  CVE-2016-4330  Candidate  In the HDF5 1.8.16 library"s failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.  Assigned (20160427)  None (candidate not yet proposed)    View
25869  CVE-2007-2512  Candidate  Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems.  Assigned (20070507)  None (candidate not yet proposed)    View
91405  CVE-2016-4586  Candidate  WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.  Assigned (20160511)  None (candidate not yet proposed)    View

Page 1074 of 20943, showing 5 records out of 104715 total, starting on record 5366, ending on 5370

Actions