CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92144  CVE-2016-5325  Candidate  CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.  Assigned (20160607)  None (candidate not yet proposed)    View
26864  CVE-2007-3507  Candidate  Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary code via a large comment value_length.  Assigned (20070702)  None (candidate not yet proposed)    View
92400  CVE-2016-5581  Candidate  Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors.  Assigned (20160616)  None (candidate not yet proposed)    View
27120  CVE-2007-3763  Candidate  The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.  Assigned (20070713)  None (candidate not yet proposed)    View
92656  CVE-2016-5836  Candidate  The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.  Assigned (20160623)  None (candidate not yet proposed)    View

Page 19702 of 20943, showing 5 records out of 104715 total, starting on record 98506, ending on 98510

Actions