CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95495  CVE-2016-8675  Candidate  The get_vlc2 function in get_bits.h in Libav before 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file, possibly related to startcode sequences during m4v detection.  Assigned (20161015)  None (candidate not yet proposed)    View
30215  CVE-2008-0098  Candidate  Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.  Assigned (20080107)  None (candidate not yet proposed)    View
95751  CVE-2016-8931  Candidate  IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.  Assigned (20161025)  None (candidate not yet proposed)    View
30471  CVE-2008-0354  Candidate  Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.  Assigned (20080118)  None (candidate not yet proposed)    View
96007  CVE-2016-9187  Candidate  Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.  Assigned (20161104)  None (candidate not yet proposed)    View

Page 1216 of 20943, showing 5 records out of 104715 total, starting on record 6076, ending on 6080

Actions