CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90859  CVE-2016-4040  Candidate  SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.  Assigned (20160419)  None (candidate not yet proposed)    View
25579  CVE-2007-2222  Candidate  Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.  Assigned (20070424)  None (candidate not yet proposed)    View
91115  CVE-2016-4296  Candidate  When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application  Assigned (20160427)  None (candidate not yet proposed)    View
25835  CVE-2007-2478  Candidate  Multiple heap-based buffer overflows in the IRC component in Cerulean Studios Trillian Pro before 3.1.5.1 allow remote attackers to corrupt memory and possibly execute arbitrary code via (1) a URL with a long UTF-8 string, which triggers the overflow when the user highlights it, or (2) a font HTML tag with a face attribute containing a long UTF-8 string.  Assigned (20070502)  None (candidate not yet proposed)    View
91371  CVE-2016-4552  Candidate  Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.  Assigned (20160506)  None (candidate not yet proposed)    View

Page 18700 of 20943, showing 5 records out of 104715 total, starting on record 93496, ending on 93500

Actions