CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91119 | CVE-2016-4300 | Candidate | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25839 | CVE-2007-2482 | Candidate | Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter. | Assigned (20070503) | None (candidate not yet proposed) | View | |
91375 | CVE-2016-4556 | Candidate | Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response. | Assigned (20160506) | None (candidate not yet proposed) | View | |
26095 | CVE-2007-2738 | Candidate | SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action. | Assigned (20070517) | None (candidate not yet proposed) | View | |
91631 | CVE-2016-4812 | Candidate | Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20160517) | None (candidate not yet proposed) | View |
Page 19620 of 20943, showing 5 records out of 104715 total, starting on record 98096, ending on 98100