CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38892  CVE-2009-1457  Candidate  Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20090428)  None (candidate not yet proposed)    View
104428  CVE-2017-7608  Candidate  The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.  Assigned (20170409)  None (candidate not yet proposed)    View
39148  CVE-2009-1713  Candidate  The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.  Assigned (20090520)  None (candidate not yet proposed)    View
104684  CVE-2017-7864  Candidate  FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.  Assigned (20170414)  None (candidate not yet proposed)    View
39404  CVE-2009-1969  Candidate  Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 19411 of 20943, showing 5 records out of 104715 total, starting on record 97051, ending on 97055

Actions