CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91363  CVE-2016-4544  Candidate  The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.  Assigned (20160505)  None (candidate not yet proposed)    View
26083  CVE-2007-2726  Candidate  BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns.  Assigned (20070516)  None (candidate not yet proposed)    View
91619  CVE-2016-4800  Candidate  The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.  Assigned (20160513)  None (candidate not yet proposed)    View
26339  CVE-2007-2982  Candidate  Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors.  Assigned (20070531)  None (candidate not yet proposed)    View
91875  CVE-2016-5056  Candidate  OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.  Assigned (20160526)  None (candidate not yet proposed)    View

Page 18657 of 20943, showing 5 records out of 104715 total, starting on record 93281, ending on 93285

Actions