CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91414 | CVE-2016-4595 | Candidate | Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover passwords by reading the screen during the login procedure. | Assigned (20160511) | None (candidate not yet proposed) | View | |
26134 | CVE-2007-2777 | Candidate | Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/. | Assigned (20070521) | None (candidate not yet proposed) | View | |
91670 | CVE-2016-4851 | Candidate | Cross-site scripting (XSS) vulnerability in Let"s PHP! simple chat before 2016-08-15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20160517) | None (candidate not yet proposed) | View | |
26390 | CVE-2007-3033 | Candidate | Cross-site scripting (XSS) vulnerability in Windows Vista Feed Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista allows user-assisted remote attackers to execute arbitrary code via an RSS feed with crafted HTML attributes, which are not properly removed and are rendered in the local zone. | Assigned (20070605) | None (candidate not yet proposed) | View | |
91926 | CVE-2016-5107 | Candidate | The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors. | Assigned (20160526) | None (candidate not yet proposed) | View |
Page 1789 of 20943, showing 5 records out of 104715 total, starting on record 8941, ending on 8945