CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
25067 | CVE-2007-1710 | Candidate | The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence. | Assigned (20070326) | None (candidate not yet proposed) | View | |
90603 | CVE-2016-3784 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160330) | None (candidate not yet proposed) | View | |
25323 | CVE-2007-1966 | Candidate | Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. | Assigned (20070410) | None (candidate not yet proposed) | View | |
90859 | CVE-2016-4040 | Candidate | SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter. | Assigned (20160419) | None (candidate not yet proposed) | View | |
25579 | CVE-2007-2222 | Candidate | Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS. | Assigned (20070424) | None (candidate not yet proposed) | View |
Page 19310 of 20943, showing 5 records out of 104715 total, starting on record 96546, ending on 96550