CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25877  CVE-2007-2520  Candidate  SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.  Assigned (20070507)  None (candidate not yet proposed)    View
91413  CVE-2016-4594  Candidate  The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows attackers to access the process list via a crafted app that makes an API call.  Assigned (20160511)  None (candidate not yet proposed)    View
26133  CVE-2007-2776  Candidate  AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.  Assigned (20070521)  None (candidate not yet proposed)    View
91669  CVE-2016-4850  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160517)  None (candidate not yet proposed)    View
26389  CVE-2007-3032  Candidate  Unspecified vulnerability in Windows Vista Contacts Gadget in Windows Vista allows user-assisted remote attackers to execute arbitrary code via crafted contact information that is not properly handled when it is imported.  Assigned (20070605)  None (candidate not yet proposed)    View

Page 1731 of 20943, showing 5 records out of 104715 total, starting on record 8651, ending on 8655

Actions