CVE List

Id CVE No. Status Description Phase Votes Comments Actions
28673  CVE-2007-5316  Candidate  SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.  Assigned (20071009)  None (candidate not yet proposed)    View
94209  CVE-2016-7389  Candidate  For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.  Assigned (20160909)  None (candidate not yet proposed)    View
28929  CVE-2007-5572  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Blog (SPHPBlog) 0.4.9 allow remote attackers to perform delete actions as administrators via (1) the block_id parameter to add_block.php or (2) the link_id parameter to add_link.php.  Assigned (20071018)  None (candidate not yet proposed)    View
94465  CVE-2016-7645  Candidate  An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.  Assigned (20160909)  None (candidate not yet proposed)    View
29185  CVE-2007-5828  Candidate  ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module.  Assigned (20071105)  None (candidate not yet proposed)    View

Page 123 of 20943, showing 5 records out of 104715 total, starting on record 611, ending on 615

Actions