CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91119  CVE-2016-4300  Candidate  Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.  Assigned (20160427)  None (candidate not yet proposed)    View
25839  CVE-2007-2482  Candidate  Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter.  Assigned (20070503)  None (candidate not yet proposed)    View
91375  CVE-2016-4556  Candidate  Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.  Assigned (20160506)  None (candidate not yet proposed)    View
26095  CVE-2007-2738  Candidate  SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.  Assigned (20070517)  None (candidate not yet proposed)    View
91631  CVE-2016-4812  Candidate  Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160517)  None (candidate not yet proposed)    View

Page 19620 of 20943, showing 5 records out of 104715 total, starting on record 98096, ending on 98100

Actions