CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23533  CVE-2007-0176  Candidate  Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.  Assigned (20070110)  None (candidate not yet proposed)    View
89069  CVE-2016-2250  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-2550. Reason: This candidate is a duplicate of CVE-2016-2550. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2016-2550 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20160208)  None (candidate not yet proposed)    View
23789  CVE-2007-0432  Candidate  BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.  Assigned (20070122)  None (candidate not yet proposed)    View
89325  CVE-2016-2506  Candidate  DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate a certain offset value, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28175045.  Assigned (20160218)  None (candidate not yet proposed)    View
24045  CVE-2007-0688  Candidate  SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20070202)  None (candidate not yet proposed)    View

Page 18856 of 20943, showing 5 records out of 104715 total, starting on record 94276, ending on 94280

Actions