CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104674 | CVE-2017-7854 | Candidate | The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file. | Assigned (20170413) | None (candidate not yet proposed) | View | |
39394 | CVE-2009-1959 | Candidate | Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow. | Assigned (20090606) | None (candidate not yet proposed) | View | |
39650 | CVE-2009-2215 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in URD before 0.6.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the fatal_error page and unspecified other components. | Assigned (20090625) | None (candidate not yet proposed) | View | |
39906 | CVE-2009-2471 | Candidate | The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper. | Assigned (20090715) | None (candidate not yet proposed) | View | |
40162 | CVE-2009-2727 | Candidate | Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15. | Assigned (20090810) | None (candidate not yet proposed) | View |
Page 18650 of 20943, showing 5 records out of 104715 total, starting on record 93246, ending on 93250