CVE List

Id CVE No. Status Description Phase Votes Comments Actions
34033  CVE-2008-3916  Candidate  Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.  Assigned (20080904)  None (candidate not yet proposed)    View
99569  CVE-2017-2749  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View
34289  CVE-2008-4172  Candidate  SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.  Assigned (20080922)  None (candidate not yet proposed)    View
99825  CVE-2017-3005  Candidate  Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability.  Assigned (20161202)  None (candidate not yet proposed)    View
34545  CVE-2008-4428  Candidate  Unrestricted file upload vulnerability in upload.php in Phlatline"s Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory.  Assigned (20081003)  None (candidate not yet proposed)    View

Page 19191 of 20943, showing 5 records out of 104715 total, starting on record 95951, ending on 95955

Actions