CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90352  CVE-2016-3533  Candidate  Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Search. NOTE: the previous information is from the July 2016 CPU. Oracle has not commented on third-party claims that this issue involves multiple open redirect vulnerabilities, which allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  Assigned (20160317)  None (candidate not yet proposed)    View
25072  CVE-2007-1715  Candidate  PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763.  Assigned (20070327)  None (candidate not yet proposed)    View
90608  CVE-2016-3789  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160330)  None (candidate not yet proposed)    View
25328  CVE-2007-1971  Candidate  SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQL commands via the query string.  Assigned (20070410)  None (candidate not yet proposed)    View
90864  CVE-2016-4045  Candidate  An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script code can be executed within a user"s context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.). The attacker needs to reside within the same context to make this attack work.  Assigned (20160420)  None (candidate not yet proposed)    View

Page 19707 of 20943, showing 5 records out of 104715 total, starting on record 98531, ending on 98535

Actions