CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88813  CVE-2016-1994  Candidate  HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.  Assigned (20160122)  None (candidate not yet proposed)    View
23533  CVE-2007-0176  Candidate  Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.  Assigned (20070110)  None (candidate not yet proposed)    View
89069  CVE-2016-2250  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-2550. Reason: This candidate is a duplicate of CVE-2016-2550. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2016-2550 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20160208)  None (candidate not yet proposed)    View
23789  CVE-2007-0432  Candidate  BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.  Assigned (20070122)  None (candidate not yet proposed)    View
89325  CVE-2016-2506  Candidate  DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate a certain offset value, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28175045.  Assigned (20160218)  None (candidate not yet proposed)    View

Page 19456 of 20943, showing 5 records out of 104715 total, starting on record 97276, ending on 97280

Actions