CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104207  CVE-2017-7387  Candidate  TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter).  Assigned (20170331)  None (candidate not yet proposed)    View
38927  CVE-2009-1492  Candidate  The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.  Assigned (20090430)  None (candidate not yet proposed)    View
104463  CVE-2017-7643  Candidate  Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program.  Assigned (20170410)  None (candidate not yet proposed)    View
39183  CVE-2009-1748  Candidate  Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.  Assigned (20090521)  None (candidate not yet proposed)    View
39439  CVE-2009-2004  Candidate  Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CVE-2007-2902.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 1249 of 20943, showing 5 records out of 104715 total, starting on record 6241, ending on 6245

Actions