CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25111  CVE-2007-1754  Candidate  PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".  Assigned (20070329)  None (candidate not yet proposed)    View
90647  CVE-2016-3828  Candidate  decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.  Assigned (20160330)  None (candidate not yet proposed)    View
25367  CVE-2007-2010  Candidate  Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.  Assigned (20070412)  None (candidate not yet proposed)    View
90903  CVE-2016-4084  Candidate  Integer signedness error in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 allows remote attackers to cause a denial of service (integer overflow and application crash) via a crafted packet that triggers an unexpected array size.  Assigned (20160424)  None (candidate not yet proposed)    View
25623  CVE-2007-2266  Candidate  Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.  Assigned (20070425)  None (candidate not yet proposed)    View

Page 1843 of 20943, showing 5 records out of 104715 total, starting on record 9211, ending on 9215

Actions