CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104168  CVE-2017-7348  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170330)  None (candidate not yet proposed)    View
38888  CVE-2009-1453  Candidate  SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). NOTE: some of these details are obtained from third party information.  Assigned (20090428)  None (candidate not yet proposed)    View
104424  CVE-2017-7604  Candidate  au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.  Assigned (20170409)  None (candidate not yet proposed)    View
39144  CVE-2009-1709  Candidate  Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."  Assigned (20090520)  None (candidate not yet proposed)    View
104680  CVE-2017-7860  Candidate  Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.  Assigned (20170414)  None (candidate not yet proposed)    View

Page 19092 of 20943, showing 5 records out of 104715 total, starting on record 95456, ending on 95460

Actions