CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94225  CVE-2016-7405  Candidate  The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.  Assigned (20160909)  None (candidate not yet proposed)    View
28945  CVE-2007-5588  Candidate  Cross-site scripting (XSS) vulnerability in mnoGoSearch before 3.2.43 allows remote attackers to inject arbitrary web script or HTML via the t parameter in search.cgi, as reachable from search.htm-dist.  Assigned (20071019)  None (candidate not yet proposed)    View
94481  CVE-2016-7661  Candidate  An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "Power Management" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.  Assigned (20160909)  None (candidate not yet proposed)    View
29201  CVE-2007-5844  Candidate  Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the selskin parameter to index.php. NOTE: this can be leveraged for remote file inclusion by including inc/boxleft.inc and specifying a URL in the xposbox[L][] array parameter.  Assigned (20071106)  None (candidate not yet proposed)    View
94737  CVE-2016-7917  Candidate  The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message"s length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 1396 of 20943, showing 5 records out of 104715 total, starting on record 6976, ending on 6980

Actions