CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27156  CVE-2007-3799  Candidate  The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.  Assigned (20070716)  None (candidate not yet proposed)    View
92692  CVE-2016-5872  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160628)  None (candidate not yet proposed)    View
27412  CVE-2007-4055  Candidate  SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this may be related to CVE-2006-4300.  Assigned (20070730)  None (candidate not yet proposed)    View
92948  CVE-2016-6128  Candidate  The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.  Assigned (20160629)  None (candidate not yet proposed)    View
27668  CVE-2007-4311  Candidate  The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number generator, related to incorrect use of the sizeof operator.  Assigned (20070813)  None (candidate not yet proposed)    View

Page 1653 of 20943, showing 5 records out of 104715 total, starting on record 8261, ending on 8265

Actions