CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26595  CVE-2007-3238  Candidate  Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.  Assigned (20070614)  None (candidate not yet proposed)    View
92131  CVE-2016-5312  Candidate  Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.  Assigned (20160606)  None (candidate not yet proposed)    View
26851  CVE-2007-3494  Candidate  Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote authenticated users to (1) read the entire database by accessing the database backup plugin via a devtools/templates/newdump_backend.html argument in the template parameter to interna/plugin.php, (2) create plugins, (3) remove plugins, (4) enable debug mode, and have other unspecified impact.  Assigned (20070629)  None (candidate not yet proposed)    View
92387  CVE-2016-5568  Candidate  Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  Assigned (20160616)  None (candidate not yet proposed)    View
27107  CVE-2007-3750  Candidate  Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via crafted Sample Table Sample Descriptor (STSD) atoms in a movie file.  Assigned (20070712)  None (candidate not yet proposed)    View

Page 18658 of 20943, showing 5 records out of 104715 total, starting on record 93286, ending on 93290

Actions