CVE List

Id CVE No. Status Description Phase Votes Comments Actions
89619  CVE-2016-2800  Candidate  The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.  Assigned (20160301)  None (candidate not yet proposed)    View
24339  CVE-2007-0982  Candidate  Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20070216)  None (candidate not yet proposed)    View
89875  CVE-2016-3056  Candidate  Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8.5.7.0 CF2016.09 allows remote authenticated users to inject arbitrary web script or HTML via crafted content.  Assigned (20160309)  None (candidate not yet proposed)    View
24595  CVE-2007-1238  Candidate  Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.  Assigned (20070303)  None (candidate not yet proposed)    View
90131  CVE-2016-3312  Candidate  ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure connection, aka "Universal Outlook Information Disclosure Vulnerability."  Assigned (20160315)  None (candidate not yet proposed)    View

Page 1547 of 20943, showing 5 records out of 104715 total, starting on record 7731, ending on 7735

Actions