CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
29934 | CVE-2007-6577 | Candidate | Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action. | Assigned (20071228) | None (candidate not yet proposed) | View | |
95470 | CVE-2016-8650 | Candidate | The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent. | Assigned (20161012) | None (candidate not yet proposed) | View | |
30190 | CVE-2008-0073 | Candidate | Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter. | Assigned (20080103) | None (candidate not yet proposed) | View | |
95726 | CVE-2016-8906 | Candidate | SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter. | Assigned (20161024) | None (candidate not yet proposed) | View | |
30446 | CVE-2008-0329 | Candidate | LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter. | Assigned (20080117) | None (candidate not yet proposed) | View |
Page 19556 of 20943, showing 5 records out of 104715 total, starting on record 97776, ending on 97780