CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
92916 | CVE-2016-6096 | Candidate | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Assigned (20160629) | None (candidate not yet proposed) | View | |
27636 | CVE-2007-4279 | Candidate | PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter. | Assigned (20070809) | None (candidate not yet proposed) | View | |
93172 | CVE-2016-6352 | Candidate | The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file. | Assigned (20160726) | None (candidate not yet proposed) | View | |
27892 | CVE-2007-4535 | Candidate | The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with a negative NewLen value within a certain UDP packet that triggers an assertion error. | Assigned (20070824) | None (candidate not yet proposed) | View | |
93428 | CVE-2016-6608 | Candidate | XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected. | Assigned (20160806) | None (candidate not yet proposed) | View |
Page 19419 of 20943, showing 5 records out of 104715 total, starting on record 97091, ending on 97095