CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26368  CVE-2007-3011  Candidate  The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter.  Assigned (20070604)  None (candidate not yet proposed)    View
91904  CVE-2016-5085  Candidate  Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.  Assigned (20160526)  None (candidate not yet proposed)    View
26624  CVE-2007-3267  Candidate  Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.  Assigned (20070619)  None (candidate not yet proposed)    View
92160  CVE-2016-5341  Candidate  The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 31470303 and external bug 211602 (and AndroidID-7225554).  Assigned (20160609)  None (candidate not yet proposed)    View
26880  CVE-2007-3523  Candidate  Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter.  Assigned (20070703)  None (candidate not yet proposed)    View

Page 1197 of 20943, showing 5 records out of 104715 total, starting on record 5981, ending on 5985

Actions