CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
27383 | CVE-2007-4026 | Candidate | epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information. | Assigned (20070726) | None (candidate not yet proposed) | View | |
92919 | CVE-2016-6099 | Candidate | IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. | Assigned (20160629) | None (candidate not yet proposed) | View | |
27639 | CVE-2007-4282 | Candidate | The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked. | Assigned (20070809) | None (candidate not yet proposed) | View | |
93175 | CVE-2016-6355 | Candidate | Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791. | Assigned (20160726) | None (candidate not yet proposed) | View | |
27895 | CVE-2007-4538 | Candidate | email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters. | Assigned (20070827) | None (candidate not yet proposed) | View |
Page 19128 of 20943, showing 5 records out of 104715 total, starting on record 95636, ending on 95640