CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38893  CVE-2009-1458  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and (3) the cat parameter in a reordercat action.  Assigned (20090428)  None (candidate not yet proposed)    View
104429  CVE-2017-7609  Candidate  elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.  Assigned (20170409)  None (candidate not yet proposed)    View
39149  CVE-2009-1714  Candidate  Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes.  Assigned (20090520)  None (candidate not yet proposed)    View
104685  CVE-2017-7865  Candidate  FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.  Assigned (20170414)  None (candidate not yet proposed)    View
39405  CVE-2009-1970  Candidate  Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 18880 of 20943, showing 5 records out of 104715 total, starting on record 94396, ending on 94400

Actions