CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91636 | CVE-2016-4817 | Candidate | lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet. | Assigned (20160517) | None (candidate not yet proposed) | View | |
26356 | CVE-2007-2999 | Candidate | Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names. | Assigned (20070604) | None (candidate not yet proposed) | View | |
91892 | CVE-2016-5073 | Candidate | CloudView NMS before 2.10a has XSS via SNMP. | Assigned (20160526) | None (candidate not yet proposed) | View | |
26612 | CVE-2007-3255 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server. | Assigned (20070619) | None (candidate not yet proposed) | View | |
92148 | CVE-2016-5329 | Candidate | VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors. | Assigned (20160607) | None (candidate not yet proposed) | View |
Page 19417 of 20943, showing 5 records out of 104715 total, starting on record 97081, ending on 97085