CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25068  CVE-2007-1711  Candidate  Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was introduced when attempting to patch CVE-2007-1701 (MOPB-31-2007).  Assigned (20070326)  None (candidate not yet proposed)    View
90604  CVE-2016-3785  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160330)  None (candidate not yet proposed)    View
25324  CVE-2007-1967  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter. NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected. This is probably an invalid report based on analysis by CVE and a third party.  Assigned (20070410)  None (candidate not yet proposed)    View
90860  CVE-2016-4041  Candidate  Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.  Assigned (20160419)  None (candidate not yet proposed)    View
25580  CVE-2007-2223  Candidate  Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.  Assigned (20070424)  None (candidate not yet proposed)    View

Page 19400 of 20943, showing 5 records out of 104715 total, starting on record 96996, ending on 97000

Actions