CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38643  CVE-2009-1208  Candidate  SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.  Assigned (20090331)  None (candidate not yet proposed)    View
104179  CVE-2017-7359  Candidate  Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.  Assigned (20170330)  None (candidate not yet proposed)    View
38899  CVE-2009-1464  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary programs via a command job, (2) stop services via a setservice job, or (3) terminate processes via a killprocess job.  Assigned (20090428)  None (candidate not yet proposed)    View
104435  CVE-2017-7615  Candidate  MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.  Assigned (20170409)  None (candidate not yet proposed)    View
39155  CVE-2009-1720  Candidate  Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.  Assigned (20090520)  None (candidate not yet proposed)    View

Page 19357 of 20943, showing 5 records out of 104715 total, starting on record 96781, ending on 96785

Actions