CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92916  CVE-2016-6096  Candidate  IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  Assigned (20160629)  None (candidate not yet proposed)    View
27636  CVE-2007-4279  Candidate  PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter.  Assigned (20070809)  None (candidate not yet proposed)    View
93172  CVE-2016-6352  Candidate  The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.  Assigned (20160726)  None (candidate not yet proposed)    View
27892  CVE-2007-4535  Candidate  The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with a negative NewLen value within a certain UDP packet that triggers an assertion error.  Assigned (20070824)  None (candidate not yet proposed)    View
93428  CVE-2016-6608  Candidate  XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.  Assigned (20160806)  None (candidate not yet proposed)    View

Page 19419 of 20943, showing 5 records out of 104715 total, starting on record 97091, ending on 97095

Actions