CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27628  CVE-2007-4271  Candidate  Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.  Assigned (20070809)  None (candidate not yet proposed)    View
93164  CVE-2016-6344  Candidate  Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.  Assigned (20160726)  None (candidate not yet proposed)    View
27884  CVE-2007-4527  Candidate  Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20070824)  None (candidate not yet proposed)    View
93420  CVE-2016-6600  Candidate  Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.  Assigned (20160804)  None (candidate not yet proposed)    View
28140  CVE-2007-4783  Candidate  The iconv_substr function in PHP 5.2.4 and earlier allows context-dependent attackers to cause (1) a denial of service (application crash) via a long string in the charset parameter, probably also requiring a long string in the str parameter; or (2) a denial of service (temporary application hang) via a long string in the str parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.  Assigned (20070910)  None (candidate not yet proposed)    View

Page 19404 of 20943, showing 5 records out of 104715 total, starting on record 97016, ending on 97020

Actions