CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95726  CVE-2016-8906  Candidate  SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.  Assigned (20161024)  None (candidate not yet proposed)    View
95727  CVE-2016-8907  Candidate  SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.  Assigned (20161024)  None (candidate not yet proposed)    View
95728  CVE-2016-8908  Candidate  SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.  Assigned (20161024)  None (candidate not yet proposed)    View
95729  CVE-2016-8909  Candidate  The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.  Assigned (20161024)  None (candidate not yet proposed)    View
95730  CVE-2016-8910  Candidate  The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.  Assigned (20161024)  None (candidate not yet proposed)    View

Page 19146 of 20943, showing 5 records out of 104715 total, starting on record 95726, ending on 95730

Actions