CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87531  CVE-2016-10037  Candidate  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.  Assigned (20161224)  None (candidate not yet proposed)    View
87532  CVE-2016-10038  Candidate  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.  Assigned (20161224)  None (candidate not yet proposed)    View
87533  CVE-2016-10039  Candidate  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.  Assigned (20161224)  None (candidate not yet proposed)    View
87535  CVE-2016-10040  Candidate  Stack-based buffer overflow in QXmlSimpleReader in Qt 4.8.5 allows remote attackers to cause a denial of service (application crash) via a xml file with multiple nested open tags.  Assigned (20161224)  None (candidate not yet proposed)    View
87528  CVE-2016-10034  Candidate  The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted e-mail address.  Assigned (20161223)  None (candidate not yet proposed)    View

Page 1459 of 20943, showing 5 records out of 104715 total, starting on record 7291, ending on 7295

Actions