CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91107 | CVE-2016-4288 | Candidate | A local privilege escalation vulnerability exists in BlueStacks App Player. The BlueStacks App Player installer creates a registry key with weak permissions that allows users to execute arbitrary programs with SYSTEM privileges. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25827 | CVE-2007-2470 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter. | Assigned (20070502) | None (candidate not yet proposed) | View | |
91363 | CVE-2016-4544 | Candidate | The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data. | Assigned (20160505) | None (candidate not yet proposed) | View | |
26083 | CVE-2007-2726 | Candidate | BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns. | Assigned (20070516) | None (candidate not yet proposed) | View | |
91619 | CVE-2016-4800 | Candidate | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes. | Assigned (20160513) | None (candidate not yet proposed) | View |
Page 18706 of 20943, showing 5 records out of 104715 total, starting on record 93526, ending on 93530