CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
37138 | CVE-2008-7021 | Candidate | Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory. | Assigned (20090821) | None (candidate not yet proposed) | View | |
102674 | CVE-2017-5854 | Candidate | base/PdfOutputStream.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37394 | CVE-2008-7277 | Candidate | Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets. | Assigned (20110318) | None (candidate not yet proposed) | View | |
102930 | CVE-2017-6110 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170221) | None (candidate not yet proposed) | View | |
37650 | CVE-2009-0215 | Candidate | Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors. | Assigned (20090120) | None (candidate not yet proposed) | View |
Page 1488 of 20943, showing 5 records out of 104715 total, starting on record 7436, ending on 7440