CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
29943 | CVE-2007-6586 | Candidate | SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php. | Assigned (20071228) | None (candidate not yet proposed) | View | |
95479 | CVE-2016-8659 | Candidate | Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket. | Assigned (20161013) | None (candidate not yet proposed) | View | |
30199 | CVE-2008-0082 | Candidate | An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors. | Assigned (20080103) | None (candidate not yet proposed) | View | |
95735 | CVE-2016-8915 | Candidate | IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649. | Assigned (20161025) | None (candidate not yet proposed) | View | |
30455 | CVE-2008-0338 | Candidate | Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI. | Assigned (20080117) | None (candidate not yet proposed) | View |
Page 19132 of 20943, showing 5 records out of 104715 total, starting on record 95656, ending on 95660