CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93051 | CVE-2016-6231 | Candidate | Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate. | Assigned (20160715) | None (candidate not yet proposed) | View | |
93052 | CVE-2016-6232 | Candidate | Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads. | Assigned (20160716) | None (candidate not yet proposed) | View | |
93053 | CVE-2016-6233 | Candidate | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [w]* in a regular expression. | Assigned (20160716) | None (candidate not yet proposed) | View | |
93054 | CVE-2016-6234 | Candidate | The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file. | Assigned (20160717) | None (candidate not yet proposed) | View | |
93055 | CVE-2016-6235 | Candidate | The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file. | Assigned (20160717) | None (candidate not yet proposed) | View |
Page 18611 of 20943, showing 5 records out of 104715 total, starting on record 93051, ending on 93055