CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37138  CVE-2008-7021  Candidate  Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory.  Assigned (20090821)  None (candidate not yet proposed)    View
102674  CVE-2017-5854  Candidate  base/PdfOutputStream.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.  Assigned (20170201)  None (candidate not yet proposed)    View
37394  CVE-2008-7277  Candidate  Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.  Assigned (20110318)  None (candidate not yet proposed)    View
102930  CVE-2017-6110  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170221)  None (candidate not yet proposed)    View
37650  CVE-2009-0215  Candidate  Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.  Assigned (20090120)  None (candidate not yet proposed)    View

Page 1508 of 20943, showing 5 records out of 104715 total, starting on record 7536, ending on 7540

Actions