CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104207 | CVE-2017-7387 | Candidate | TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter). | Assigned (20170331) | None (candidate not yet proposed) | View | |
38927 | CVE-2009-1492 | Candidate | The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments. | Assigned (20090430) | None (candidate not yet proposed) | View | |
104463 | CVE-2017-7643 | Candidate | Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program. | Assigned (20170410) | None (candidate not yet proposed) | View | |
39183 | CVE-2009-1748 | Candidate | Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter. | Assigned (20090521) | None (candidate not yet proposed) | View | |
39439 | CVE-2009-2004 | Candidate | Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CVE-2007-2902. | Assigned (20090608) | None (candidate not yet proposed) | View |
Page 1249 of 20943, showing 5 records out of 104715 total, starting on record 6241, ending on 6245