CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36631  CVE-2008-6514  Candidate  The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.  Assigned (20090324)  None (candidate not yet proposed)    View
102167  CVE-2017-5347  Candidate  SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.  Assigned (20170111)  None (candidate not yet proposed)    View
36887  CVE-2008-6770  Candidate  YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt.  Assigned (20090429)  None (candidate not yet proposed)    View
102423  CVE-2017-5603  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for Jitsi 2.5.5061 - 2.9.5544.  Assigned (20170128)  None (candidate not yet proposed)    View
37143  CVE-2008-7026  Candidate  Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.  Assigned (20090821)  None (candidate not yet proposed)    View

Page 1861 of 20943, showing 5 records out of 104715 total, starting on record 9301, ending on 9305

Actions