CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92944  CVE-2016-6124  Candidate  IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.  Assigned (20160629)  None (candidate not yet proposed)    View
27664  CVE-2007-4307  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7 and earlier allow remote attackers to inject arbitrary web script or HTML via the next parameter to (1) addaddress.php, (2) editshipdetails.php, (3) register.php, or (4) login.php in secure/.  Assigned (20070813)  None (candidate not yet proposed)    View
93200  CVE-2016-6380  Candidate  The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.  Assigned (20160726)  None (candidate not yet proposed)    View
27920  CVE-2007-4563  Candidate  Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user"s group permissions to logical J2EE server processes, which allows local users to gain privileges.  Assigned (20070827)  None (candidate not yet proposed)    View
93456  CVE-2016-6636  Candidate  The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.1; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 mishandles redirect_uri subdomains, which allows remote attackers to obtain implicit access tokens via a modified subdomain.  Assigned (20160810)  None (candidate not yet proposed)    View

Page 1332 of 20943, showing 5 records out of 104715 total, starting on record 6656, ending on 6660

Actions