CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36631 | CVE-2008-6514 | Candidate | The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920. | Assigned (20090324) | None (candidate not yet proposed) | View | |
102167 | CVE-2017-5347 | Candidate | SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php. | Assigned (20170111) | None (candidate not yet proposed) | View | |
36887 | CVE-2008-6770 | Candidate | YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt. | Assigned (20090429) | None (candidate not yet proposed) | View | |
102423 | CVE-2017-5603 | Candidate | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for Jitsi 2.5.5061 - 2.9.5544. | Assigned (20170128) | None (candidate not yet proposed) | View | |
37143 | CVE-2008-7026 | Candidate | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/. | Assigned (20090821) | None (candidate not yet proposed) | View |
Page 1861 of 20943, showing 5 records out of 104715 total, starting on record 9301, ending on 9305