CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38885  CVE-2009-1450  Candidate  PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter.  Assigned (20090428)  None (candidate not yet proposed)    View
104421  CVE-2017-7601  Candidate  LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.  Assigned (20170409)  None (candidate not yet proposed)    View
39141  CVE-2009-1706  Candidate  The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstances upon (1) disabling of the feature or (2) exit of the application, which makes it easier for remote web servers to track users via a cookie.  Assigned (20090520)  None (candidate not yet proposed)    View
104677  CVE-2017-7857  Candidate  FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.  Assigned (20170414)  None (candidate not yet proposed)    View
39397  CVE-2009-1962  Candidate  Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.  Assigned (20090606)  None (candidate not yet proposed)    View

Page 18881 of 20943, showing 5 records out of 104715 total, starting on record 94401, ending on 94405

Actions