CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95840  CVE-2016-9020  Candidate  SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.  Assigned (20161025)  None (candidate not yet proposed)    View
95839  CVE-2016-9019  Candidate  SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.  Assigned (20161025)  None (candidate not yet proposed)    View
95838  CVE-2016-9018  Candidate  Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.  Assigned (20161025)  None (candidate not yet proposed)    View
95837  CVE-2016-9017  Candidate  Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction function in the jsdump.c component.  Assigned (20161025)  None (candidate not yet proposed)    View
95836  CVE-2016-9016  Candidate  Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.  Assigned (20161025)  None (candidate not yet proposed)    View

Page 1776 of 20943, showing 5 records out of 104715 total, starting on record 8876, ending on 8880

Actions