CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91107  CVE-2016-4288  Candidate  A local privilege escalation vulnerability exists in BlueStacks App Player. The BlueStacks App Player installer creates a registry key with weak permissions that allows users to execute arbitrary programs with SYSTEM privileges.  Assigned (20160427)  None (candidate not yet proposed)    View
25827  CVE-2007-2470  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter.  Assigned (20070502)  None (candidate not yet proposed)    View
91363  CVE-2016-4544  Candidate  The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.  Assigned (20160505)  None (candidate not yet proposed)    View
26083  CVE-2007-2726  Candidate  BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns.  Assigned (20070516)  None (candidate not yet proposed)    View
91619  CVE-2016-4800  Candidate  The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.  Assigned (20160513)  None (candidate not yet proposed)    View

Page 18706 of 20943, showing 5 records out of 104715 total, starting on record 93526, ending on 93530

Actions