CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91156  CVE-2016-4337  Candidate  SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.  Assigned (20160427)  None (candidate not yet proposed)    View
25876  CVE-2007-2519  Candidate  Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0. NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions.  Assigned (20070507)  None (candidate not yet proposed)    View
91412  CVE-2016-4593  Candidate  The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.  Assigned (20160511)  None (candidate not yet proposed)    View
26132  CVE-2007-2775  Candidate  AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.  Assigned (20070521)  None (candidate not yet proposed)    View
91668  CVE-2016-4849  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160517)  None (candidate not yet proposed)    View

Page 1629 of 20943, showing 5 records out of 104715 total, starting on record 8141, ending on 8145

Actions