CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39147 | CVE-2009-1712 | Candidate | WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element. | Assigned (20090520) | None (candidate not yet proposed) | View | |
104683 | CVE-2017-7863 | Candidate | FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c. | Assigned (20170414) | None (candidate not yet proposed) | View | |
39403 | CVE-2009-1968 | Candidate | Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search. | Assigned (20090608) | None (candidate not yet proposed) | View | |
39659 | CVE-2009-2224 | Candidate | Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter. | Assigned (20090626) | None (candidate not yet proposed) | View | |
39915 | CVE-2009-2480 | Candidate | Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20090716) | None (candidate not yet proposed) | View |
Page 19332 of 20943, showing 5 records out of 104715 total, starting on record 96656, ending on 96660