CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
88813 | CVE-2016-1994 | Candidate | HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors. | Assigned (20160122) | None (candidate not yet proposed) | View | |
23533 | CVE-2007-0176 | Candidate | Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter. | Assigned (20070110) | None (candidate not yet proposed) | View | |
89069 | CVE-2016-2250 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-2550. Reason: This candidate is a duplicate of CVE-2016-2550. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2016-2550 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Assigned (20160208) | None (candidate not yet proposed) | View | |
23789 | CVE-2007-0432 | Candidate | BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities. | Assigned (20070122) | None (candidate not yet proposed) | View | |
89325 | CVE-2016-2506 | Candidate | DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate a certain offset value, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28175045. | Assigned (20160218) | None (candidate not yet proposed) | View |
Page 19456 of 20943, showing 5 records out of 104715 total, starting on record 97276, ending on 97280