CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36619  CVE-2008-6502  Candidate  Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (CSRF), cross-site scripting (XSS), or other impacts.  Assigned (20090320)  None (candidate not yet proposed)    View
102155  CVE-2017-5335  Candidate  The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.  Assigned (20170110)  None (candidate not yet proposed)    View
36875  CVE-2008-6758  Candidate  Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.  Assigned (20090428)  None (candidate not yet proposed)    View
102411  CVE-2017-5591  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.  Assigned (20170125)  None (candidate not yet proposed)    View
37131  CVE-2008-7014  Candidate  fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value.  Assigned (20090818)  None (candidate not yet proposed)    View

Page 1544 of 20943, showing 5 records out of 104715 total, starting on record 7716, ending on 7720

Actions