CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96001 | CVE-2016-9181 | Candidate | perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure. | Assigned (20161104) | None (candidate not yet proposed) | View | |
30721 | CVE-2008-0604 | Candidate | The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions. | Assigned (20080205) | None (candidate not yet proposed) | View | |
96257 | CVE-2016-9437 | Candidate | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) and possibly memory corruption via a crafted HTML page. | Assigned (20161118) | None (candidate not yet proposed) | View | |
30977 | CVE-2008-0860 | Candidate | Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors related to null DACLs. | Assigned (20080220) | None (candidate not yet proposed) | View | |
96513 | CVE-2016-9693 | Candidate | IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim"s machine. IBM Reference #: 1998655. | Assigned (20161201) | None (candidate not yet proposed) | View |
Page 126 of 20943, showing 5 records out of 104715 total, starting on record 626, ending on 630