CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96001  CVE-2016-9181  Candidate  perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.  Assigned (20161104)  None (candidate not yet proposed)    View
30721  CVE-2008-0604  Candidate  The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.  Assigned (20080205)  None (candidate not yet proposed)    View
96257  CVE-2016-9437  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) and possibly memory corruption via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
30977  CVE-2008-0860  Candidate  Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors related to null DACLs.  Assigned (20080220)  None (candidate not yet proposed)    View
96513  CVE-2016-9693  Candidate  IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim"s machine. IBM Reference #: 1998655.  Assigned (20161201)  None (candidate not yet proposed)    View

Page 126 of 20943, showing 5 records out of 104715 total, starting on record 626, ending on 630

Actions