CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
25623 | CVE-2007-2266 | Candidate | Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter. | Assigned (20070425) | None (candidate not yet proposed) | View | |
91159 | CVE-2016-4340 | Candidate | The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25879 | CVE-2007-2522 | Candidate | Stack-based buffer overflow in the inoweb Console Server in CA Anti-Virus for the Enterprise r8, Threat Manager r8, Anti-Spyware for the Enterprise r8, and Protection Suites r3 allows remote attackers to execute arbitrary code via a long (1) username or (2) password. | Assigned (20070508) | None (candidate not yet proposed) | View | |
91415 | CVE-2016-4596 | Candidate | QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4597, CVE-2016-4600, and CVE-2016-4602. | Assigned (20160511) | None (candidate not yet proposed) | View | |
26135 | CVE-2007-2778 | Candidate | Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to index.php and other unspecified PHP scripts. | Assigned (20070521) | None (candidate not yet proposed) | View |
Page 1891 of 20943, showing 5 records out of 104715 total, starting on record 9451, ending on 9455