CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26375  CVE-2007-3018  Candidate  activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.  Assigned (20070604)  None (candidate not yet proposed)    View
91911  CVE-2016-5092  Candidate  Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging the autolearn feature.  Assigned (20160526)  None (candidate not yet proposed)    View
26631  CVE-2007-3274  Candidate  Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.  Assigned (20070619)  None (candidate not yet proposed)    View
92167  CVE-2016-5348  Candidate  The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 29555864.  Assigned (20160609)  None (candidate not yet proposed)    View
26887  CVE-2007-3530  Candidate  PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.  Assigned (20070703)  None (candidate not yet proposed)    View

Page 1738 of 20943, showing 5 records out of 104715 total, starting on record 8686, ending on 8690

Actions