CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
26345 | CVE-2007-2988 | Candidate | A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php. | Assigned (20070531) | None (candidate not yet proposed) | View | |
91881 | CVE-2016-5062 | Candidate | The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans. | Assigned (20160526) | None (candidate not yet proposed) | View | |
26601 | CVE-2007-3244 | Candidate | SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug." | Assigned (20070614) | None (candidate not yet proposed) | View | |
92137 | CVE-2016-5318 | Candidate | Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff. | Assigned (20160606) | None (candidate not yet proposed) | View | |
26857 | CVE-2007-3500 | Candidate | Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie. | Assigned (20070629) | None (candidate not yet proposed) | View |
Page 19152 of 20943, showing 5 records out of 104715 total, starting on record 95756, ending on 95760