CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38891  CVE-2009-1456  Candidate  Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.  Assigned (20090428)  None (candidate not yet proposed)    View
104427  CVE-2017-7607  Candidate  The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.  Assigned (20170409)  None (candidate not yet proposed)    View
39147  CVE-2009-1712  Candidate  WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.  Assigned (20090520)  None (candidate not yet proposed)    View
104683  CVE-2017-7863  Candidate  FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.  Assigned (20170414)  None (candidate not yet proposed)    View
39403  CVE-2009-1968  Candidate  Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 18721 of 20943, showing 5 records out of 104715 total, starting on record 93601, ending on 93605

Actions