CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87527  CVE-2016-10033  Candidate  The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property.  Assigned (20161222)  None (candidate not yet proposed)    View
22247  CVE-2006-6143  Candidate  The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.  Assigned (20061128)  None (candidate not yet proposed)    View
87783  CVE-2016-10266  Candidate  LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.  Assigned (20170324)  None (candidate not yet proposed)    View
22503  CVE-2006-6399  Candidate  SQL injection vulnerability in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. NOTE: the provenance of this information is unknown; details are obtained from third party sources.  Assigned (20061207)  None (candidate not yet proposed)    View
88039  CVE-2016-1220  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20151226)  None (candidate not yet proposed)    View

Page 19009 of 20943, showing 5 records out of 104715 total, starting on record 95041, ending on 95045

Actions