CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88586  CVE-2016-1767  Candidate  QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1768.  Assigned (20160113)  None (candidate not yet proposed)    View
23306  CVE-2006-7202  Candidate  The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.  Assigned (20070509)  None (candidate not yet proposed)    View
88842  CVE-2016-2023  Candidate  HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.  Assigned (20160122)  None (candidate not yet proposed)    View
23562  CVE-2007-0205  Candidate  Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.  Assigned (20070111)  None (candidate not yet proposed)    View
89098  CVE-2016-2279  Candidate  Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160209)  None (candidate not yet proposed)    View

Page 1444 of 20943, showing 5 records out of 104715 total, starting on record 7216, ending on 7220

Actions