CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27925  CVE-2007-4568  Candidate  Integer overflow in the build_range function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted size values, which triggers a heap-based buffer overflow.  Assigned (20070828)  None (candidate not yet proposed)    View
93461  CVE-2016-6641  Candidate  Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160810)  None (candidate not yet proposed)    View
28181  CVE-2007-4824  Candidate  Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.  Assigned (20070911)  None (candidate not yet proposed)    View
93717  CVE-2016-6897  Candidate  Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.  Assigned (20160822)  None (candidate not yet proposed)    View
28437  CVE-2007-5080  Candidate  Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.  Assigned (20070924)  None (candidate not yet proposed)    View

Page 1712 of 20943, showing 5 records out of 104715 total, starting on record 8556, ending on 8560

Actions