CVE List

Id CVE No. Status Description Phase Votes Comments Actions
28417  CVE-2007-5060  Candidate  Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values.  Assigned (20070924)  None (candidate not yet proposed)    View
93953  CVE-2016-7133  Candidate  Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.  Assigned (20160902)  None (candidate not yet proposed)    View
28673  CVE-2007-5316  Candidate  SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.  Assigned (20071009)  None (candidate not yet proposed)    View
94209  CVE-2016-7389  Candidate  For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.  Assigned (20160909)  None (candidate not yet proposed)    View
28929  CVE-2007-5572  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Blog (SPHPBlog) 0.4.9 allow remote attackers to perform delete actions as administrators via (1) the block_id parameter to add_block.php or (2) the link_id parameter to add_link.php.  Assigned (20071018)  None (candidate not yet proposed)    View

Page 125 of 20943, showing 5 records out of 104715 total, starting on record 621, ending on 625

Actions