CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
90864 | CVE-2016-4045 | Candidate | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). The attacker needs to reside within the same context to make this attack work. | Assigned (20160420) | None (candidate not yet proposed) | View | |
25584 | CVE-2007-2227 | Candidate | The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability." | Assigned (20070424) | None (candidate not yet proposed) | View | |
91120 | CVE-2016-4301 | Candidate | Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25840 | CVE-2007-2483 | Candidate | Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter. | Assigned (20070503) | None (candidate not yet proposed) | View | |
91376 | CVE-2016-4557 | Candidate | The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor. | Assigned (20160506) | None (candidate not yet proposed) | View |
Page 19700 of 20943, showing 5 records out of 104715 total, starting on record 98496, ending on 98500