CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
38891 | CVE-2009-1456 | Candidate | Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter. | Assigned (20090428) | None (candidate not yet proposed) | View | |
104427 | CVE-2017-7607 | Candidate | The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. | Assigned (20170409) | None (candidate not yet proposed) | View | |
39147 | CVE-2009-1712 | Candidate | WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element. | Assigned (20090520) | None (candidate not yet proposed) | View | |
104683 | CVE-2017-7863 | Candidate | FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c. | Assigned (20170414) | None (candidate not yet proposed) | View | |
39403 | CVE-2009-1968 | Candidate | Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search. | Assigned (20090608) | None (candidate not yet proposed) | View |
Page 18721 of 20943, showing 5 records out of 104715 total, starting on record 93601, ending on 93605