CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36621 | CVE-2008-6504 | Candidate | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a u0023 representation for the # character. | Assigned (20090323) | None (candidate not yet proposed) | View | |
102157 | CVE-2017-5337 | Candidate | Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate. | Assigned (20170110) | None (candidate not yet proposed) | View | |
36877 | CVE-2008-6760 | Candidate | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter. | Assigned (20090428) | None (candidate not yet proposed) | View | |
102413 | CVE-2017-5593 | Candidate | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for Psi+ (0.16.563.580 - 0.16.571.627). | Assigned (20170125) | None (candidate not yet proposed) | View | |
37133 | CVE-2008-7016 | Candidate | tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server. | Assigned (20090821) | None (candidate not yet proposed) | View |
Page 1092 of 20943, showing 5 records out of 104715 total, starting on record 5456, ending on 5460