CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38630  CVE-2009-1195  Candidate  The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.  Assigned (20090331)  None (candidate not yet proposed)    View
104166  CVE-2017-7346  Candidate  The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device.  Assigned (20170330)  None (candidate not yet proposed)    View
38886  CVE-2009-1451  Candidate  Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.  Assigned (20090428)  None (candidate not yet proposed)    View
104422  CVE-2017-7602  Candidate  LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.  Assigned (20170409)  None (candidate not yet proposed)    View
39142  CVE-2009-1707  Candidate  Race condition in the Reset Safari implementation in Apple Safari before 4.0 on Windows might allow local users to read stored web-site passwords via unspecified vectors.  Assigned (20090520)  None (candidate not yet proposed)    View

Page 18933 of 20943, showing 5 records out of 104715 total, starting on record 94661, ending on 94665

Actions