CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91115 | CVE-2016-4296 | Candidate | When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application | Assigned (20160427) | None (candidate not yet proposed) | View | |
25835 | CVE-2007-2478 | Candidate | Multiple heap-based buffer overflows in the IRC component in Cerulean Studios Trillian Pro before 3.1.5.1 allow remote attackers to corrupt memory and possibly execute arbitrary code via (1) a URL with a long UTF-8 string, which triggers the overflow when the user highlights it, or (2) a font HTML tag with a face attribute containing a long UTF-8 string. | Assigned (20070502) | None (candidate not yet proposed) | View | |
91371 | CVE-2016-4552 | Candidate | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message. | Assigned (20160506) | None (candidate not yet proposed) | View | |
26091 | CVE-2007-2734 | Candidate | The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic. | Assigned (20070516) | None (candidate not yet proposed) | View | |
91627 | CVE-2016-4808 | Candidate | Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim. | Assigned (20160515) | None (candidate not yet proposed) | View |
Page 19311 of 20943, showing 5 records out of 104715 total, starting on record 96551, ending on 96555