CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29943  CVE-2007-6586  Candidate  SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php.  Assigned (20071228)  None (candidate not yet proposed)    View
95479  CVE-2016-8659  Candidate  Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.  Assigned (20161013)  None (candidate not yet proposed)    View
30199  CVE-2008-0082  Candidate  An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors.  Assigned (20080103)  None (candidate not yet proposed)    View
95735  CVE-2016-8915  Candidate  IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649.  Assigned (20161025)  None (candidate not yet proposed)    View
30455  CVE-2008-0338  Candidate  Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.  Assigned (20080117)  None (candidate not yet proposed)    View

Page 19132 of 20943, showing 5 records out of 104715 total, starting on record 95656, ending on 95660

Actions