CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
38892 | CVE-2009-1457 | Candidate | Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20090428) | None (candidate not yet proposed) | View | |
104428 | CVE-2017-7608 | Candidate | The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. | Assigned (20170409) | None (candidate not yet proposed) | View | |
39148 | CVE-2009-1713 | Candidate | The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors. | Assigned (20090520) | None (candidate not yet proposed) | View | |
104684 | CVE-2017-7864 | Candidate | FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c. | Assigned (20170414) | None (candidate not yet proposed) | View | |
39404 | CVE-2009-1969 | Candidate | Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors. | Assigned (20090608) | None (candidate not yet proposed) | View |
Page 19411 of 20943, showing 5 records out of 104715 total, starting on record 97051, ending on 97055