CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29159  CVE-2007-5802  Candidate  Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: this can be leveraged to obtain the path by including a local PHP script with a duplicate function declaration.  Assigned (20071102)  None (candidate not yet proposed)    View
94695  CVE-2016-7875  Candidate  Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable integer overflow vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.  Assigned (20160909)  None (candidate not yet proposed)    View
29415  CVE-2007-6058  Candidate  Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module.  Assigned (20071120)  None (candidate not yet proposed)    View
94951  CVE-2016-8131  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160909)  None (candidate not yet proposed)    View
29671  CVE-2007-6314  Candidate  BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to the file name in the URL.  Assigned (20071211)  None (candidate not yet proposed)    View

Page 18997 of 20943, showing 5 records out of 104715 total, starting on record 94981, ending on 94985

Actions