CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93051  CVE-2016-6231  Candidate  Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.  Assigned (20160715)  None (candidate not yet proposed)    View
93052  CVE-2016-6232  Candidate  Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.  Assigned (20160716)  None (candidate not yet proposed)    View
93053  CVE-2016-6233  Candidate  The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [w]* in a regular expression.  Assigned (20160716)  None (candidate not yet proposed)    View
93054  CVE-2016-6234  Candidate  The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.  Assigned (20160717)  None (candidate not yet proposed)    View
93055  CVE-2016-6235  Candidate  The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.  Assigned (20160717)  None (candidate not yet proposed)    View

Page 18611 of 20943, showing 5 records out of 104715 total, starting on record 93051, ending on 93055

Actions