CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104674  CVE-2017-7854  Candidate  The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.  Assigned (20170413)  None (candidate not yet proposed)    View
39394  CVE-2009-1959  Candidate  Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.  Assigned (20090606)  None (candidate not yet proposed)    View
39650  CVE-2009-2215  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in URD before 0.6.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the fatal_error page and unspecified other components.  Assigned (20090625)  None (candidate not yet proposed)    View
39906  CVE-2009-2471  Candidate  The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.  Assigned (20090715)  None (candidate not yet proposed)    View
40162  CVE-2009-2727  Candidate  Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.  Assigned (20090810)  None (candidate not yet proposed)    View

Page 18650 of 20943, showing 5 records out of 104715 total, starting on record 93246, ending on 93250

Actions