CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
38643 | CVE-2009-1208 | Candidate | SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings. | Assigned (20090331) | None (candidate not yet proposed) | View | |
104179 | CVE-2017-7359 | Candidate | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | Assigned (20170330) | None (candidate not yet proposed) | View | |
38899 | CVE-2009-1464 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary programs via a command job, (2) stop services via a setservice job, or (3) terminate processes via a killprocess job. | Assigned (20090428) | None (candidate not yet proposed) | View | |
104435 | CVE-2017-7615 | Candidate | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. | Assigned (20170409) | None (candidate not yet proposed) | View | |
39155 | CVE-2009-1720 | Candidate | Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information. | Assigned (20090520) | None (candidate not yet proposed) | View |
Page 19357 of 20943, showing 5 records out of 104715 total, starting on record 96781, ending on 96785