CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26345  CVE-2007-2988  Candidate  A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php.  Assigned (20070531)  None (candidate not yet proposed)    View
91881  CVE-2016-5062  Candidate  The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.  Assigned (20160526)  None (candidate not yet proposed)    View
26601  CVE-2007-3244  Candidate  SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug."  Assigned (20070614)  None (candidate not yet proposed)    View
92137  CVE-2016-5318  Candidate  Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.  Assigned (20160606)  None (candidate not yet proposed)    View
26857  CVE-2007-3500  Candidate  Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.  Assigned (20070629)  None (candidate not yet proposed)    View

Page 19152 of 20943, showing 5 records out of 104715 total, starting on record 95756, ending on 95760

Actions