CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93716  CVE-2016-6896  Candidate  Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random read operations that deplete the entropy pool.  Assigned (20160822)  None (candidate not yet proposed)    View
28436  CVE-2007-5079  Candidate  Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.  Assigned (20070924)  None (candidate not yet proposed)    View
93972  CVE-2016-7152  Candidate  The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.  Assigned (20160906)  None (candidate not yet proposed)    View
28692  CVE-2007-5335  Candidate  Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.  Assigned (20071010)  None (candidate not yet proposed)    View
94228  CVE-2016-7408  Candidate  The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 1617 of 20943, showing 5 records out of 104715 total, starting on record 8081, ending on 8085

Actions