CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91146  CVE-2016-4327  Candidate  Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.  Assigned (20160427)  None (candidate not yet proposed)    View
25866  CVE-2007-2509  Candidate  CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.  Assigned (20070507)  None (candidate not yet proposed)    View
91402  CVE-2016-4583  Candidate  WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.  Assigned (20160511)  None (candidate not yet proposed)    View
26122  CVE-2007-2765  Candidate  blockhosts.py in BlockHosts before 2.0.3 does not properly parse daemon log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by logging in through ssh using a login name containing certain strings with an IP address, which is not properly handled by a regular expression, a related issue to CVE-2006-6301.  Assigned (20070518)  None (candidate not yet proposed)    View
91658  CVE-2016-4839  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160517)  None (candidate not yet proposed)    View

Page 1448 of 20943, showing 5 records out of 104715 total, starting on record 7236, ending on 7240

Actions