CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26351  CVE-2007-2994  Candidate  SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a fullnews action, a different vector than CVE-2007-0693.  Assigned (20070604)  None (candidate not yet proposed)    View
91887  CVE-2016-5068  Candidate  Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.  Assigned (20160526)  None (candidate not yet proposed)    View
26607  CVE-2007-3250  Candidate  SQL injection vulnerability in mod_banners.php in Elxis CMS before 2006.4 20070613 allows remote attackers to execute arbitrary SQL commands via the mb_tracker cookie. NOTE: the product was patched without updating the version number; later downloads of 2006.4 are not affected.  Assigned (20070618)  None (candidate not yet proposed)    View
92143  CVE-2016-5324  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160606)  None (candidate not yet proposed)    View
26863  CVE-2007-3506  Candidate  The ft_bitmap_assure_buffer function in src/base/ftbimap.c in FreeType 2.3.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors involving bitmap fonts, related to a "memory buffer overwrite bug."  Assigned (20070702)  None (candidate not yet proposed)    View

Page 19621 of 20943, showing 5 records out of 104715 total, starting on record 98101, ending on 98105

Actions