CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91879 | CVE-2016-5060 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description, (2) email, or (3) username parameter to user/save. | Assigned (20160526) | None (candidate not yet proposed) | View | |
26599 | CVE-2007-3242 | Candidate | The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the titles of items in a personal menu. | Assigned (20070614) | None (candidate not yet proposed) | View | |
92135 | CVE-2016-5316 | Candidate | Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool. | Assigned (20160606) | None (candidate not yet proposed) | View | |
26855 | CVE-2007-3498 | Candidate | Cross-site scripting (XSS) vulnerability in smoketests/configForm.php in HTML Purifier before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "unescaped print_r output." | Assigned (20070629) | None (candidate not yet proposed) | View | |
92391 | CVE-2016-5572 | Candidate | Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors. | Assigned (20160616) | None (candidate not yet proposed) | View |
Page 18980 of 20943, showing 5 records out of 104715 total, starting on record 94896, ending on 94900