CVE List

Id CVE No. Status Description Phase Votes Comments Actions
31723  CVE-2008-1606  Candidate  Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a ".." (dot dot backslash) in the file parameter to importData.jsp, and (3) list directory contents via a .. (dot dot) in the dir parameter to manager/fileManager.jsp.  Assigned (20080401)  None (candidate not yet proposed)    View
97259  CVE-2017-0440  Candidate  An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33252788. References: QC-CR#1095770.  Assigned (20161129)  None (candidate not yet proposed)    View
31979  CVE-2008-1862  Candidate  ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypass this check via (1) POST or (2) COOKIE variables, a different vector than CVE-2006-4488. NOTE: this can be leveraged to conduct PHP remote file inclusion attacks via a URL in the (a) new_exbb[home_path] or (b) exbb[home_path] parameter to modules/threadstop/threadstop.php.  Assigned (20080417)  None (candidate not yet proposed)    View
97515  CVE-2017-0696  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161129)  None (candidate not yet proposed)    View
32235  CVE-2008-2118  Candidate  SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20080508)  None (candidate not yet proposed)    View

Page 19309 of 20943, showing 5 records out of 104715 total, starting on record 96541, ending on 96545

Actions