CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91114 | CVE-2016-4295 | Candidate | When opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalculation leading to a heap overlow can be made to occur in Hancom Office 2014. The vulnerability occurs when processing data for a formula used to render a chart via the HncChartPlugin.hplg library. Due to a lack of bounds-checking when incrementing an index that is used for writing into a buffer for formulae, the application can be made to write pointer data outside its bounds which can lead to code execution under the context of the application. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25834 | CVE-2007-2477 | Candidate | ** DISPUTED ** PHP remote file inclusion vulnerability in phpMyChat.php3 in phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code via a URL in the {ChatPath} parameter. NOTE: this has been disputed by multiple third parties and CVE because $ChatPath is set to a constant value. | Assigned (20070502) | None (candidate not yet proposed) | View | |
91370 | CVE-2016-4551 | Candidate | The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621. | Assigned (20160506) | None (candidate not yet proposed) | View | |
26090 | CVE-2007-2733 | Candidate | Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448. | Assigned (20070516) | None (candidate not yet proposed) | View | |
91626 | CVE-2016-4807 | Candidate | Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin). | Assigned (20160515) | None (candidate not yet proposed) | View |
Page 18621 of 20943, showing 5 records out of 104715 total, starting on record 93101, ending on 93105