CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25835  CVE-2007-2478  Candidate  Multiple heap-based buffer overflows in the IRC component in Cerulean Studios Trillian Pro before 3.1.5.1 allow remote attackers to corrupt memory and possibly execute arbitrary code via (1) a URL with a long UTF-8 string, which triggers the overflow when the user highlights it, or (2) a font HTML tag with a face attribute containing a long UTF-8 string.  Assigned (20070502)  None (candidate not yet proposed)    View
91371  CVE-2016-4552  Candidate  Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.  Assigned (20160506)  None (candidate not yet proposed)    View
26091  CVE-2007-2734  Candidate  The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.  Assigned (20070516)  None (candidate not yet proposed)    View
91627  CVE-2016-4808  Candidate  Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.  Assigned (20160515)  None (candidate not yet proposed)    View
26347  CVE-2007-2990  Candidate  Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var/run/.inetd.uds Unix domain socket file.  Assigned (20070531)  None (candidate not yet proposed)    View

Page 19324 of 20943, showing 5 records out of 104715 total, starting on record 96616, ending on 96620

Actions