CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93709  CVE-2016-6889  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160819)  None (candidate not yet proposed)    View
28429  CVE-2007-5072  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via certain user_colors array parameters to certain user_style.php files under themes/, as demonstrated by the user_colors[bg_color] parameter.  Assigned (20070924)  None (candidate not yet proposed)    View
93965  CVE-2016-7145  Candidate  The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.  Assigned (20160905)  None (candidate not yet proposed)    View
28685  CVE-2007-5328  Candidate  The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure."  Assigned (20071010)  None (candidate not yet proposed)    View
94221  CVE-2016-7401  Candidate  The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 1079 of 20943, showing 5 records out of 104715 total, starting on record 5391, ending on 5395

Actions