CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
22765 | CVE-2006-6661 | Candidate | Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters. | Assigned (20061220) | None (candidate not yet proposed) | View | |
88301 | CVE-2016-1482 | Candidate | Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130. | Assigned (20160104) | None (candidate not yet proposed) | View | |
23021 | CVE-2006-6917 | Candidate | Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is not properly handled in TAPEENG.dll 11.5.3884.0. | Assigned (20070111) | None (candidate not yet proposed) | View | |
88557 | CVE-2016-1738 | Candidate | dyld in Apple OS X before 10.11.4 allows attackers to bypass a code-signing protection mechanism via a modified app. | Assigned (20160113) | None (candidate not yet proposed) | View | |
23277 | CVE-2006-7173 | Candidate | Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php. | Assigned (20070320) | None (candidate not yet proposed) | View |
Page 19455 of 20943, showing 5 records out of 104715 total, starting on record 97271, ending on 97275