CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
29678 | CVE-2007-6321 | Candidate | Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands. | Assigned (20071211) | None (candidate not yet proposed) | View | |
95214 | CVE-2016-8394 | Candidate | An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31913197. | Assigned (20161005) | None (candidate not yet proposed) | View | |
29934 | CVE-2007-6577 | Candidate | Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action. | Assigned (20071228) | None (candidate not yet proposed) | View | |
95470 | CVE-2016-8650 | Candidate | The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent. | Assigned (20161012) | None (candidate not yet proposed) | View | |
30190 | CVE-2008-0073 | Candidate | Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter. | Assigned (20080103) | None (candidate not yet proposed) | View |
Page 18945 of 20943, showing 5 records out of 104715 total, starting on record 94721, ending on 94725