CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37102  CVE-2008-6985  Candidate  Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.  Assigned (20090817)  None (candidate not yet proposed)    View
102638  CVE-2017-5818  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170201)  None (candidate not yet proposed)    View
37358  CVE-2008-7241  Candidate  Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified users for requests related to a logout, probably a forced logout.  Assigned (20090917)  None (candidate not yet proposed)    View
102894  CVE-2017-6074  Candidate  The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.  Assigned (20170217)  None (candidate not yet proposed)    View
37614  CVE-2009-0179  Candidate  libmikmod 3.1.11 through 3.2.0, as used by MikMod and possibly other products, allows user-assisted attackers to cause a denial of service (application crash) by loading an XM file.  Assigned (20090120)  None (candidate not yet proposed)    View

Page 19558 of 20943, showing 5 records out of 104715 total, starting on record 97786, ending on 97790

Actions