CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29961  CVE-2007-6604  Candidate  Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) the pg parameter to an arbitrary module, as demonstrated by reading a password hash in a .dtb file under dati/membri/ or by executing embedded PHP code in images under uploads/avatar/.  Assigned (20071231)  None (candidate not yet proposed)    View
95497  CVE-2016-8677  Candidate  The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a crafted image file, which triggers a memory allocation failure.  Assigned (20161015)  None (candidate not yet proposed)    View
30217  CVE-2008-0100  Candidate  Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file.  Assigned (20080107)  None (candidate not yet proposed)    View
95753  CVE-2016-8933  Candidate  IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.  Assigned (20161025)  None (candidate not yet proposed)    View
30473  CVE-2008-0356  Candidate  Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.  Assigned (20080118)  None (candidate not yet proposed)    View

Page 1375 of 20943, showing 5 records out of 104715 total, starting on record 6871, ending on 6875

Actions