CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22765  CVE-2006-6661  Candidate  Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.  Assigned (20061220)  None (candidate not yet proposed)    View
88301  CVE-2016-1482  Candidate  Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130.  Assigned (20160104)  None (candidate not yet proposed)    View
23021  CVE-2006-6917  Candidate  Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is not properly handled in TAPEENG.dll 11.5.3884.0.  Assigned (20070111)  None (candidate not yet proposed)    View
88557  CVE-2016-1738  Candidate  dyld in Apple OS X before 10.11.4 allows attackers to bypass a code-signing protection mechanism via a modified app.  Assigned (20160113)  None (candidate not yet proposed)    View
23277  CVE-2006-7173  Candidate  Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.  Assigned (20070320)  None (candidate not yet proposed)    View

Page 19455 of 20943, showing 5 records out of 104715 total, starting on record 97271, ending on 97275

Actions