CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104683 | CVE-2017-7863 | Candidate | FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c. | Assigned (20170414) | None (candidate not yet proposed) | View | |
39403 | CVE-2009-1968 | Candidate | Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search. | Assigned (20090608) | None (candidate not yet proposed) | View | |
39659 | CVE-2009-2224 | Candidate | Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter. | Assigned (20090626) | None (candidate not yet proposed) | View | |
39915 | CVE-2009-2480 | Candidate | Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20090716) | None (candidate not yet proposed) | View | |
40171 | CVE-2009-2736 | Candidate | Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action. | Assigned (20090810) | None (candidate not yet proposed) | View |
Page 19345 of 20943, showing 5 records out of 104715 total, starting on record 96721, ending on 96725