CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23534  CVE-2007-0177  Candidate  Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20070110)  None (candidate not yet proposed)    View
89070  CVE-2016-2251  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none.  Assigned (20160208)  None (candidate not yet proposed)    View
23790  CVE-2007-0433  Candidate  Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.  Assigned (20070122)  None (candidate not yet proposed)    View
89326  CVE-2016-2507  Candidate  Integer overflow in codecs/on2/h264dec/source/h264bsd_storage.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28532266.  Assigned (20160218)  None (candidate not yet proposed)    View
24046  CVE-2007-0689  Candidate  MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.  Assigned (20070203)  None (candidate not yet proposed)    View

Page 19546 of 20943, showing 5 records out of 104715 total, starting on record 97726, ending on 97730

Actions