CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90853  CVE-2016-4034  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160415)  None (candidate not yet proposed)    View
25573  CVE-2007-2216  Candidate  The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka "ActiveX Object Vulnerability."  Assigned (20070424)  None (candidate not yet proposed)    View
91109  CVE-2016-4290  Candidate  When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a block of data within the file. When calculating this length, the application will use a value from the file and add a constant to it without checking whether the addition of the constant will cause the integer to overflow which will cause the buffer to be undersized when the application tries to copy file data into it. This allows one to overwrite contiguous data in the heap which can lead to code-execution under the context of the application.  Assigned (20160427)  None (candidate not yet proposed)    View
25829  CVE-2007-2472  Candidate  Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20070502)  None (candidate not yet proposed)    View
91365  CVE-2016-4546  Candidate  Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call.  Assigned (20160505)  None (candidate not yet proposed)    View

Page 18860 of 20943, showing 5 records out of 104715 total, starting on record 94296, ending on 94300

Actions