CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104684  CVE-2017-7864  Candidate  FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.  Assigned (20170414)  None (candidate not yet proposed)    View
39404  CVE-2009-1969  Candidate  Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View
39660  CVE-2009-2225  Candidate  Stack-based buffer overflow in SureThing CD/DVD Labeler 5.1.616 trial version allows user-assisted remote attackers to execute arbitrary code via a crafted (1) m3u or (2) pls playlist file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20090626)  None (candidate not yet proposed)    View
39916  CVE-2009-2481  Candidate  mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.  Assigned (20090716)  None (candidate not yet proposed)    View
40172  CVE-2009-2737  Candidate  The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.  Assigned (20090810)  None (candidate not yet proposed)    View

Page 19401 of 20943, showing 5 records out of 104715 total, starting on record 97001, ending on 97005

Actions