CVE List

Id CVE No. Status Description Phase Votes Comments Actions
28437  CVE-2007-5080  Candidate  Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.  Assigned (20070924)  None (candidate not yet proposed)    View
93973  CVE-2016-7153  Candidate  The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.  Assigned (20160906)  None (candidate not yet proposed)    View
28693  CVE-2007-5336  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-5339. Reason: This candidate is a reservation duplicate of CVE-2007-5339. Notes: All CVE users should reference CVE-2007-5339 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20071010)  None (candidate not yet proposed)    View
94229  CVE-2016-7409  Candidate  The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.  Assigned (20160909)  None (candidate not yet proposed)    View
28949  CVE-2007-5592  Candidate  Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Setting[OPT_includepath] parameter to (1) adminhelp.php; and (2) admin.incl.php, (3) reg.incl.php, (4) help.incl.php, (5) gbook.incl.php, and (6) core/core.incl.php in modules/.  Assigned (20071019)  None (candidate not yet proposed)    View

Page 1735 of 20943, showing 5 records out of 104715 total, starting on record 8671, ending on 8675

Actions