CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93420  CVE-2016-6600  Candidate  Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.  Assigned (20160804)  None (candidate not yet proposed)    View
28140  CVE-2007-4783  Candidate  The iconv_substr function in PHP 5.2.4 and earlier allows context-dependent attackers to cause (1) a denial of service (application crash) via a long string in the charset parameter, probably also requiring a long string in the str parameter; or (2) a denial of service (temporary application hang) via a long string in the str parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.  Assigned (20070910)  None (candidate not yet proposed)    View
93676  CVE-2016-6856  Candidate  Cross-site scripting (XSS) vulnerability in the Inbox Search feature in Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to inject arbitrary web script or HTML via the itemsperpage parameter.  Assigned (20160818)  None (candidate not yet proposed)    View
28396  CVE-2007-5039  Candidate  Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtQueryValueKey, (4) NtSetSystemInformation, and (5) NtSetValueKey kernel SSDT hooks.  Assigned (20070923)  None (candidate not yet proposed)    View
93932  CVE-2016-7112  Candidate  The EN100 Ethernet module before 4.29 for Siemens SIPROTEC 4 and SIPROTEC Compact devices allows remote attackers to bypass authentication and obtain administrative access via unspecified HTTP traffic.  Assigned (20160830)  None (candidate not yet proposed)    View

Page 19394 of 20943, showing 5 records out of 104715 total, starting on record 96966, ending on 96970

Actions