CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
27925 | CVE-2007-4568 | Candidate | Integer overflow in the build_range function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted size values, which triggers a heap-based buffer overflow. | Assigned (20070828) | None (candidate not yet proposed) | View | |
93461 | CVE-2016-6641 | Candidate | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20160810) | None (candidate not yet proposed) | View | |
28181 | CVE-2007-4824 | Candidate | Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory. | Assigned (20070911) | None (candidate not yet proposed) | View | |
93717 | CVE-2016-6897 | Candidate | Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896. | Assigned (20160822) | None (candidate not yet proposed) | View | |
28437 | CVE-2007-5080 | Candidate | Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow. | Assigned (20070924) | None (candidate not yet proposed) | View |
Page 1712 of 20943, showing 5 records out of 104715 total, starting on record 8556, ending on 8560