CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95216  CVE-2016-8396  Candidate  An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-31249105.  Assigned (20161005)  None (candidate not yet proposed)    View
29936  CVE-2007-6579  Candidate  Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to assetclassgroupview.php; the (5) subnet_id parameter to nodelist.php; and unspecified other vectors. NOTE: it was later reported that the vlanview.php and vlandel.php vectors are also in 0.4.  Assigned (20071228)  None (candidate not yet proposed)    View
95472  CVE-2016-8652  Candidate  The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.  Assigned (20161012)  None (candidate not yet proposed)    View
30192  CVE-2008-0075  Candidate  Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.  Assigned (20080103)  None (candidate not yet proposed)    View
95728  CVE-2016-8908  Candidate  SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.  Assigned (20161024)  None (candidate not yet proposed)    View

Page 19104 of 20943, showing 5 records out of 104715 total, starting on record 95516, ending on 95520

Actions