CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17054  CVE-2006-0950  Candidate  unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with ".." (dot dot) sequences in a filename.  Assigned (20060301)  None (candidate not yet proposed)    View
78607  CVE-2015-1330  Candidate  unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.  Assigned (20150122)  None (candidate not yet proposed)    View
95218  CVE-2016-8398  Candidate  Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.  Assigned (20161005)  None (candidate not yet proposed)    View
87350  CVE-2016-1000112  Candidate  Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin  Assigned (20160720)  None (candidate not yet proposed)    View
87609  CVE-2016-10108  Candidate  Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.  Assigned (20170103)  None (candidate not yet proposed)    View

Page 18612 of 20943, showing 5 records out of 104715 total, starting on record 93056, ending on 93060

Actions