CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29678  CVE-2007-6321  Candidate  Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.  Assigned (20071211)  None (candidate not yet proposed)    View
95214  CVE-2016-8394  Candidate  An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31913197.  Assigned (20161005)  None (candidate not yet proposed)    View
29934  CVE-2007-6577  Candidate  Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.  Assigned (20071228)  None (candidate not yet proposed)    View
95470  CVE-2016-8650  Candidate  The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.  Assigned (20161012)  None (candidate not yet proposed)    View
30190  CVE-2008-0073  Candidate  Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.  Assigned (20080103)  None (candidate not yet proposed)    View

Page 18945 of 20943, showing 5 records out of 104715 total, starting on record 94721, ending on 94725

Actions