CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30476  CVE-2008-0359  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.  Assigned (20080118)  None (candidate not yet proposed)    View
96012  CVE-2016-9192  Candidate  A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account. More Information: CSCvb68043. Known Affected Releases: 4.3(2039) 4.3(748). Known Fixed Releases: 4.3(4019) 4.4(225).  Assigned (20161106)  None (candidate not yet proposed)    View
30732  CVE-2008-0615  Candidate  Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.  Assigned (20080205)  None (candidate not yet proposed)    View
96268  CVE-2016-9448  Candidate  The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297.  Assigned (20161118)  None (candidate not yet proposed)    View
30988  CVE-2008-0871  Candidate  Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.  Assigned (20080221)  None (candidate not yet proposed)    View

Page 1613 of 20943, showing 5 records out of 104715 total, starting on record 8061, ending on 8065

Actions