CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96088  CVE-2016-9268  Candidate  Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.  Assigned (20161110)  None (candidate not yet proposed)    View
96089  CVE-2016-9269  Candidate  Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality. This was resolved in Version 6.5 CP 1737.  Assigned (20161110)  None (candidate not yet proposed)    View
96090  CVE-2016-9270  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161111)  None (candidate not yet proposed)    View
96091  CVE-2016-9271  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161111)  None (candidate not yet proposed)    View
96092  CVE-2016-9272  Candidate  A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.  Assigned (20161111)  None (candidate not yet proposed)    View

Page 18611 of 20943, showing 5 records out of 104715 total, starting on record 93051, ending on 93055

Actions