CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25356  CVE-2007-1999  Candidate  PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.  Assigned (20070412)  None (candidate not yet proposed)    View
90892  CVE-2016-4073  Candidate  Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted mb_strcut call.  Assigned (20160423)  None (candidate not yet proposed)    View
25612  CVE-2007-2255  Candidate  Multiple PHP remote file inclusion vulnerabilities in Download-Engine 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) eng_dir parameter to addmember.php, (2) lang_path parameter to admin/enginelib/class.phpmailer.php, and the (3) spaw_root parameter to admin/includes/spaw/dialogs/colorpicker.php, different vectors than CVE-2006-5291 and CVE-2006-5459. NOTE: vector 3 might be an issue in SPAW.  Assigned (20070425)  None (candidate not yet proposed)    View
91148  CVE-2016-4329  Candidate  A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV self-protection mechanism.  Assigned (20160427)  None (candidate not yet proposed)    View
25868  CVE-2007-2511  Candidate  Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.  Assigned (20070507)  None (candidate not yet proposed)    View

Page 1605 of 20943, showing 5 records out of 104715 total, starting on record 8021, ending on 8025

Actions