CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40728  CVE-2009-3293  Candidate  Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."  Assigned (20090922)  None (candidate not yet proposed)    View
43430  CVE-2010-0846  Candidate  Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows remote attackers to execute arbitrary code, related to an "invalid assignment" and inconsistent length values in a JPEG image encoder (JPEGImageEncoderImpl).  Assigned (20100303)  None (candidate not yet proposed)    View
43425  CVE-2010-0841  Candidate  Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the Java Runtime Environment that allows remote attackers to execute arbitrary code via a JPEG image that contains subsample dimensions with large values, related to JPEGImageReader and "stepX".  Assigned (20100303)  None (candidate not yet proposed)    View
33793  CVE-2008-3676  Candidate  Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long series of IMAP commands.  Assigned (20080814)  None (candidate not yet proposed)    View
32976  CVE-2008-2859  Candidate  Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."  Assigned (20080624)  None (candidate not yet proposed)    View

Page 19465 of 20943, showing 5 records out of 104715 total, starting on record 97321, ending on 97325

Actions