CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91363 | CVE-2016-4544 | Candidate | The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data. | Assigned (20160505) | None (candidate not yet proposed) | View | |
26083 | CVE-2007-2726 | Candidate | BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns. | Assigned (20070516) | None (candidate not yet proposed) | View | |
91619 | CVE-2016-4800 | Candidate | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes. | Assigned (20160513) | None (candidate not yet proposed) | View | |
26339 | CVE-2007-2982 | Candidate | Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors. | Assigned (20070531) | None (candidate not yet proposed) | View | |
91875 | CVE-2016-5056 | Candidate | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK. | Assigned (20160526) | None (candidate not yet proposed) | View |
Page 18657 of 20943, showing 5 records out of 104715 total, starting on record 93281, ending on 93285