CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93974  CVE-2016-7154  Candidate  Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.  Assigned (20160906)  None (candidate not yet proposed)    View
28694  CVE-2007-5337  Candidate  Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.  Assigned (20071010)  None (candidate not yet proposed)    View
94230  CVE-2016-7410  Candidate  The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.  Assigned (20160909)  None (candidate not yet proposed)    View
28950  CVE-2007-5593  Candidate  install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.  Assigned (20071019)  None (candidate not yet proposed)    View
94486  CVE-2016-7666  Candidate  An issue was discovered in certain Apple products. Transporter before 1.9.2 is affected. The issue involves the "iTMSTransporter" component, which allows attackers to obtain sensitive information via a crafted EPUB.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 1793 of 20943, showing 5 records out of 104715 total, starting on record 8961, ending on 8965

Actions