CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93166  CVE-2016-6346  Candidate  RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.  Assigned (20160726)  None (candidate not yet proposed)    View
27886  CVE-2007-4529  Candidate  The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin"s own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3) AdminStartServer, and (4) AdminStopServer privileges; and administration of arbitrary virtual servers via a request to a .tscmd URI with a modified serverid parameter, as demonstrated by (a) add_server.tscmd, (b) ask_delete_server.tscmd, (c) start_server.tscmd, and (d) stop_server.tscmd.  Assigned (20070824)  None (candidate not yet proposed)    View
93422  CVE-2016-6602  Candidate  ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.  Assigned (20160804)  None (candidate not yet proposed)    View
28142  CVE-2007-4785  Candidate  Sony Micro Vault Fingerprint Access Software, as distributed with Sony Micro Vault USM-F USB flash drives, installs a driver that hides a directory under %WINDIR%, which might allow remote attackers to bypass malware detection by placing files in this directory.  Assigned (20070910)  None (candidate not yet proposed)    View
93678  CVE-2016-6858  Candidate  Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x before 5.1.0.11, 5.1.1.x before 5.1.1.12, 5.2.0.x and 5.3.0.x before 5.3.0.10, 5.4.x before 5.4.0.9, 5.5.0.x before 5.5.0.9, 5.5.1.x before 5.5.1.10, 5.6.x before 5.6.0.8, and 5.7.x before 5.7.0.9 allows remote authenticated users to inject arbitrary web script or HTML via the Name field.  Assigned (20160818)  None (candidate not yet proposed)    View

Page 18942 of 20943, showing 5 records out of 104715 total, starting on record 94706, ending on 94710

Actions